Ledger says Ethereum signing flaw was already fixed
Covered by 2 sources · 2 articles
Ledger addressed a vulnerability in its Ethereum app that allowed malicious decentralized applications to swap transaction details after a user reviewed them on-device. The flaw exploited a gap in the clear signing process, creating a window where the displayed transaction could diverge from what was actually executed. The hardware-wallet maker released a patch and has advised users to update both firmware and applications to close the vulnerability.
The timing suggests Ledger resolved the issue proactively rather than responding to an active exploit, though the company did not disclose when the vulnerability was first discovered or how many users may have been affected.
- Ledger patched a signing vulnerability where malicious dApps could alter Ethereum transactions after on-device approval without users noticing.
- The company has released fixes for both firmware and applications, with users advised to update immediately.
- No details were shared on the vulnerability's discovery timeline or potential user impact.
All coverage
Ledger Patches Ethereum Signing Flaw Before Researchers Disclose It
Ledger has patched a vulnerability in its Ethereum hardware-wallet app that could allow a malicious dApp to replace a transaction during the approval process while the device continued showing users the transaction they originally reviewed.…
Ledger says Ethereum signing flaw was already fixed
Ledger says it fixed a vulnerability affecting certain Ethereum clear signing flows and urged users to update their firmware and applications.