Ledger says the viral “hack” was already patched, but two real bugs still needed fixing

1 hour ago 2



Crypto wallet maker Ledger is urging its Ethereum app users to update again after two signing flaws remained in its previous security release.The hardware-wallet maker published Ethereum app version 1.22.3 on Aug. 25, closing vulnerabilities that could hide operations from a device review or authorize a token approval in place of an expected payment.The update follows controversy over a separate Ethereum signing flaw reproduced by rival wallet maker OneKey. That issue, tracked as LSB-023, affected older versions and allowed a compromised host to interleave commands so that transaction parameters could change after being displayed but before signing.Ledger said OneKey demonstrated the bug against version 1.22.1 after the company had already fixed it in Ethereum app 1.22.2, released Aug. 13.“No Ledger user was hacked,” Ledger’s security team said, describing the demonstration as a laboratory reproduction involving outdated software. The company said it had found no evidence of exploitation in the wild.Ledger Chief Technology Officer Charles Guillemet made the same distinction, saying reproducing an already-patched flaw did not amount to “hacking Ledger.”Version 1.22.2, however, did n...

Read Entire Article