Ledger Patches Ethereum Signing Flaw Before Researchers Disclose It
0
0

Ledger has patched a vulnerability in its Ethereum hardware-wallet app that could allow a malicious dApp to replace a transaction during the approval process while the device continued showing users the transaction they originally reviewed.
Security firm TestMachine disclosed the signature-substitution flaw on August 21 after reproducing it on Ledger hardware. Ledger had already shipped Ethereum app version 1.22.2 on August 12, with its release history listing security fixes for the update.
Malicious dApp Could Change the Transaction Before Signing
The flaw affected the command flow between a connected dApp and Ledger’s Ethereum application. A malicious application with direct device access through WebHID could interfere while a transaction review remained open, replacing the signing context before the user approved it.
The device could therefore continue displaying the original transaction while preparing a different transaction for the final signature. TestMachine demonstrated the issue using a benign ETH transfer that could be substituted with a token approval, creating a path for users to authorize something different from the transaction shown on the hardware screen.
Version 1.22.2 blocks competing signing commands while a review is pending and tightens how the application maintains signing state during the approval flow. The fix preserves the link between the transaction displayed on the secure screen and the transaction ultimately signed by the device.
Ledger Says Donjon Found the Bug Before Disclosure
Ledger CTO Charles Guillemet said the company’s Donjon security team had already identified and fixed the bug roughly two weeks before TestMachine published its findings, using AI-assisted security tools during the review.
Guillemet also criticized the disclosure process, saying TestMachine contacted Ledger’s bounty program after the patch had already shipped and then published its findings without completing the normal responsible-disclosure process. Users running current device firmware and Ethereum app version 1.22.2 are protected against the flaw.
The discovery adds another example of AI entering wallet-security review. A recent Bitcoin Red Team audit used AI-assisted analysis alongside human researchers to identify thousands of potential security issues across Bitcoin wallets and infrastructure.
Hardware Wallet Vendors Push Security Updates
Ledger’s fix arrives less than a week after BitBox released firmware 9.26.5 to patch two severe vulnerabilities, including a memory-corruption flaw that could allow arbitrary code execution under specific conditions.
Hardware-wallet security has faced heavier scrutiny since the Coldcard seed-generation failure exposed wallets created with insufficient randomness. The resulting Bitcoin drains were estimated at as much as $132 million as multiple attackers raced to identify vulnerable addresses.
Ledger’s Ethereum app 1.22.2, released August 12, is the patched version covering the newly disclosed signing flaw.
The post Ledger Patches Ethereum Signing Flaw Before Researchers Disclose It appeared first on Crypto Adventure.
0
0
Securely connect the portfolio you’re using to start.





