No, Ledger Wasn’t Hacked: Vulnerable Ethereum App was Patched before Exploit, Company Says

In brief - OneKey reproduced a transaction-replacement attack against version 1.22.1 of Ledger’s Ethereum app. - Ledger says it fixed the vulnerability in version 1.22.2 before OneKey published its test and has seen no evidence of attacks against users. - Ledger recommends...

In brief – OneKey reproduced a transaction-replacement attack against version 1.22.1 of Ledger’s Ethereum app. – Ledger says it fixed the vulnerability in version 1.22.2 before OneKey published its test and has seen no evidence of attacks against users. – Ledger recommends…

stalling Ethereum app version 1.22.3 or later and checking the app version on the device. Cryptocurrency wallet developer Ledger rejects claims that it had been hacked after researchers at rival wallet maker OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger’s Ethereum app

On Thursday, Yishi Wang, founder and CEO of OneKey, said on X that the company’s Anzen security team recreated the attack against Ethereum app version 1.22.1 in a lab. “The bug is a race condition between the transaction display logic and the underlying transaction buffer,” Wang wrote. “An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.” That would mean a hacker who had compromised the software communicating with a vulnerable Ledger app could show the user a legitimate Ethereum transaction, then replace its details before signing, redirecting funds to the hacker’s wallet without the change appearing on the device. Ledger Chief Technology Officer Charles Guillemet rejected OneKey’s characterization, saying that reproducing an already-patched bug does not amount to “hacking Ledger.” “What this thread describes is a vulnerability in an outdated version of the Ethereum app,” he responded on X. “It was identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post.” In a security bulletin published on Thursday, Ledger said the flaw could cause an affected app to display one transaction while signing another. An attacker would first need to control communications between the device and its host through malware, a compromised wallet app or a hostile website.

Ledger said it found…

Leave a Reply

Your email address will not be published. Required fields are marked *