Ledger patched an Ethereum app bug that could show one transaction and sign another

요약:Ledger users should update the Ethereum app to version 1.22.2, which fixes a race condition where a malicious dApp with WebHID access could inject a second signing command during an active review, causing the device to sign substituted data while displaying original details. Security firm TestMachine validated the issue on Ledger Flex and said shared code affected Nano X, Nano S Plus, Stax, and Apex. Ledgers fix blocks new signing sessions during active reviews and rejects approval callbacks when the state no longer matches. Ledger CTO Charles Guillemet said Donjon found the bug earlier and deployed the fix around Aug. 12–13. No in-the-wild exploitation, lost funds, or private-key extraction was confirmed. The issue is separate from the native Zilliqa app flaw and the 2023 Connect Kit compromise.

Ledger users should update the Ethereum app to version 1.22.2 after official code changes showed that a malicious dApp or other connected host could start a second signing command while a transaction was still under review.

Related Asset Ethereum #2 ETH · $2,497.37 24-hour change: up 1.69% 24H Up 1.69% 7D Up 31.46% 30D Up 32.66%

In the path described by security company TestMachine, pressing approve could return a signature for substituted data instead of the transaction shown on the device.

TestMachine said on Aug. 22 that the attack required a dApp with WebHID access. The group said a second command could replace the transaction held in memory without opening a new review, leaving the original details on screen while the device signed the replacement.

Related Company Ledger Crypto hardware wallets

It said the behavior was validated on Ledger Flex.

Ledgers code history shows one official fix commit saying new signing commands could tear down an active review before returning an error. Another added state checks because approval callbacks previously signed without confirming that the app remained in the expected signing state.

Version 1.22.2 closes that documented path by refusing a new signing session during an active review and rejecting an approval callback when the state no longer matches. The reviewed sources establish a code-level fix for those entry and callback defects.

Diagram showing the signing-state race described for Ledgers Ethereum app and the safeguards added in version 1.22.2.

TestMachine asserted that shared code extended the issue to Nano X, Nano S Plus, Stax, and Apex, and the tagged app manifest lists those models alongside Flex as build targets.

Ledgers release comparison starts from version 1.22.1, while the earliest affected app release remains undisclosed.

Ledgers changelog dates 1.22.2 to Aug. 12, GitHub shows the signed tag on Aug. 13, and TestMachine said on Aug. 22 that the fix was not yet released.

Ledger CTO Charles Guillemet said on Aug. 23 that Ledger Donjon had found a bug in “certain clear signing flows” and deployed the fix about two weeks earlier. The sources leave open whether TestMachine was referring to distribution through Ledger Wallet.

Related Person Charles Guillemet CTO · Ledger

Guillemet said Donjon found the bug before TestMachine contacted Ledgers bounty program, while TestMachine said its Azimuth system found the issue and that it shared and verified the finding with Ledger.

Users should confirm that Ethereum app 1.22.2 is installed. Guillemet also advised keeping device firmware, apps, and client software current, although the public sources give no firmware minimum specific to this flaw.

They report no confirmed in-the-wild exploitation, lost funds, or private-key extraction.

The issue is separate from the native Zilliqa Ledger app flaw involving Schnorr nonce leakage and the 2023 Connect Kit compromise, which involved a malicious JavaScript library and reported losses.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

巴基斯坦開放加密貨幣許可門戶,現有企業截止日期為9月5日

다음

比特币突破 81000 美元 黄金创 25 年新高