Ethereum: Ledger claims that vulnerabilities in Ethereum applications have been fixed, with no attacks on users detected
Coinpaper
49m ago
Ai Focus
Ledger indicates that vulnerabilities in the old version of Ethereum applications have been fixed in versions 1.22.2 and subsequent versions, and no attacks on users in real environments have been detected.
Helpful
No.Help

Hardware wallet manufacturer Ledger has responded to a vulnerability in an Ethereum application. The company disclosed that the issue, which has been recently discussed, appeared in the older version Ethereum App 1.22.1. Relevant fixes were deployed before the experimental reproduction results of OneKey were published. Currently, there is no evidence indicating that this vulnerability has been used to attack users in a real-world environment.

On August 27th, Wang Yishi, the founder of OneKey, stated on the X platform that his security team Anzen had reproduced a "transaction replacement" attack in a test environment. According to his description, the vulnerability is related to a race condition between the transaction display logic and the underlying transaction buffer. If an attacker has control over the communication between the device and the host, they may be able to replace the content to be signed while the user is verifying a legitimate transaction.

For a vulnerability to be exploited, it is necessary to first control the communication link.

In the security bulletin issued on the same day, Ledger stated that this issue could result in the device screen displaying one transaction, but in reality, another transaction was signed. However, there are clear prerequisites for such an attack to be successful: the attacker must first gain control of the communication link between the hardware wallet and the computer or mobile phone, either through malware, a compromised wallet application, or by intervening with a malicious website.

The company's Chief Technology Officer, Charles Guillemet, stated that re-running a fixed vulnerability in an older version does not equate to "Ledger being hacked." He mentioned that the company discovered this issue within its internal security processes and had already patched it in the Ethereum App 1.22.2 release on August 13th, which was prior to OneKey making the related tests public.

Fixed in two steps in August.

Ledger reveals that the first step was to launch Ethereum App version 1.22.2 on August 13, which added additional protections. The second step was to fix an underlying issue in Secure SDK version 26.6.1 on August 21, and based on that, to rebuild the related applications accordingly. The company currently recommends that users upgrade to version 1.22.3 or a later version, as this version also fixes another transaction display vulnerability.

  • Affected version is Ethereum App 1.22.1
  • 1.22.2 released a fix on August 13th.
  • Versions 1.22.3 and above are the currently recommended versions.

The company claims to have not seen any evidence of a real attack.

Ledger indicates that, to date, there is no evidence of this vulnerability being exploited outside of the laboratory. Guillemet also states that no users have been attacked by hackers due to this issue. The current information suggests that the related reproductions are part of laboratory tests, and not new attacks in the real world.

The security research team under Ledger also stated on the X platform that this incident highlights the need for hardware wallets to have the capability for software updates. The team noted that it is not uncommon for software vulnerabilities to occur; the key lies in whether manufacturers can quickly push fixes to already sold devices after identifying the issues.

Additional information:Earlier this month, users of Coldcard offline hardware wallets encountered a theft incident involving over $130 million in Bitcoin. Ledger executives stated at the time that this was a warning to the entire hardware wallet industry.

Tip
$0
Like
0
Save
0
Views 28
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: Genius Group Plans to Raise $1.2 Billion to Expand AI and Bitcoin Treasury
Genius Group plans to raise $1.2 billion to expand its AI and Bitcoin treasury, and intends to resume buying Bitcoin in the fourth quarter of 2026.
CoinPedia
·2026-08-28 03:24:14
6
web3: Foreign media: Bank stablecoins are not the same as tokenized deposits
Foreign media analyzes the differences between bank stablecoins, tokenized deposits, and CBDC, suggesting that it is more likely that all three will coexist rather than just one model remaining.
Coinpaper
·2026-08-28 02:23:24
14
web3: Jiaxin Financial Plans to Expand Crypto Products to Include SOL and Other Assets
AXA Financial Plans Expands Crypto Products, Plans to Add SOL, AVAX, LINK; During the Same Period, SOL ETF Had a Weekly Net Inflow of Over $74 Million.
SolanaFloor
·2026-08-28 02:11:21
18
Foreign media: If NVIDIA acquires Hugging Face, it will rewrite open-source AI
Foreign media believes that if NVIDIA completes the acquisition of Hugging Face, it could reshape the distribution and infrastructure landscape of the open-source AI.
Coinpaper
·2026-08-28 01:47:01
14
Google Launches Pokémon Collaborative Edition Fitbit Air
Google Launches Pokémon Collaborative Version Fitbit Air, Supporting Linkage with Pok é mon Sleep, and Equipped with AI Health Guidance Function.
TechCrunch
·2026-08-28 01:23:56
17
View More