Ledger Ethereum App Vulnerability Discovered, But Users Can Already Protect Themselves
A vulnerability in Ledger’s Ethereum app could allow a malicious dApp to have a user sign a different transaction from the one shown on their hardware wallet screen. The security issue sounds serious, but there is an important detail: Ledger closed the hole on 12 August. Users running the latest version of the Ethereum app are protected, according to Ledger.
Ledger could sign different transaction from the one shown on screen
The problem lies in certain so-called clear signing processes. This feature is supposed to ensure that a Ledger user sees, in plain language on the device, exactly what they are signing.
Security firm TestMachine, however, describes a scenario in which a malicious dApp sends a second command to the Ledger during that check. While the user believes they are sending 0.01 Ethereum to a known wallet, the final signature could in fact relate to a completely different transaction, according to the researchers.
In their example, a normal Ethereum transaction is transformed into approval for an attacker to spend an unlimited amount of DAI. The Ledger screen meanwhile continues to show the original transaction.
TestMachine says it found the vulnerability with its AI system, Azimuth, and tested it on a Ledger Flex. According to the company, shared code also appears in several other Ledger devices.
Ledger says vulnerability had already been fixed
The discussion takes an unusual turn because the vulnerability should no longer be active. Ledger CTO Charles Guillemet says the company’s internal security team, Ledger Donjon, discovered the bug itself using AI research.
Ledger then released version 1.22.2 of its Ethereum app on 12 August. The public changelog for that version only contains a general reference to security fixes. No separate security bulletin about this vulnerability was published.
Guillemet is critical of the way TestMachine went public with the discovery. According to him, the company only contacted the bounty programme after Ledger had already rolled out the fix. He especially disputes the impression that Ledger users are still vulnerable.
Ledger users should check their Ethereum app
For users, the main advice comes down to checking their software. Anyone using the Ethereum app on Ledger should make sure version 1.22.2 or a newer version is installed.
The case has also prompted debate about how security vulnerabilities are communicated. TestMachine believes the vulnerability is serious enough to warrant detailed warning to users, while Ledger argues the publication needlessly causes fear because the problem has already been fixed.
On one important point, the two sides ultimately agree: the vulnerability did exist and an update closes it. Those who keep their Ledger apps up to date are protected against this specific attack, according to Ledger.
Not financial advice. CryptoTips We are not a financial advisor and the content on this website is not financial advice. All information on this website is informative and not a recommendation to buy or sell anything. Consult an expert when making financial decisions and only invest money you can afford. You are responsible for your own investments. We use affiliate referrals and may receive commissions for these. Read our full disclaimer.
Affiliate disclosure. Some links on this site are partner/affiliate links. If you sign up with a partner through such a link, we may receive a commission at no extra cost to you. This never influences our reporting. Read our editorial guidelines.