Crypto pockets maker Ledger is urging its Ethereum app customers to replace once more after two signing flaws remained in its earlier safety launch.
The hardware-wallet maker revealed Ethereum app model 1.22.3 on Aug. 25, closing vulnerabilities that might cover operations from a tool evaluation or authorize a token approval instead of an anticipated cost.
The replace follows controversy over a separate Ethereum signing flaw reproduced by rival pockets maker OneKey. That concern, tracked as LSB-023, affected older variations and allowed a compromised host to interleave instructions in order that transaction parameters might change after being displayed however earlier than signing.
Ledger stated OneKey demonstrated the bug in opposition to model 1.22.1 after the corporate had already fastened it in Ethereum app 1.22.2, launched Aug. 13.
“No Ledger consumer was hacked,” Ledger’s safety group stated, describing the demonstration as a laboratory copy involving outdated software program. The corporate stated it had discovered no proof of exploitation within the wild.
Ledger Chief Know-how Officer Charles Guillemet made the identical distinction, saying reproducing an already-patched flaw didn’t quantity to “hacking Ledger.”
Model 1.22.2, nevertheless, didn’t shut each recognized Ethereum-app vulnerability on Ledger. As an alternative, two separate flaws, LSB-024 and LSB-025, remained till the discharge of 1.22.3.
Two extra signing paths remained uncovered
LSB-024 affected how the Ethereum app processed arrays of operations throughout clear signing.
The app learn the variety of operations utilizing a 16-bit worth however saved the remaining rely in an 8-bit area. In Ledger’s proof of idea, an array containing 257 operations wrapped the counter again to at least one, inflicting the gadget to show solely the ultimate operation regardless that its signature approved your complete batch.
Exploitation required a compromised host and an unusually massive attacker-controlled operation array. Ledger examined the state of affairs on a non-public community fork and reported no real-user losses.
The second vulnerability, LSB-025, affected the token-payment path utilized by Ledger’s Alternate software throughout swaps.

Ledger’s app checked the token, amount, and vacation spot however didn’t confirm that the requested motion was really a cost. A malicious or compromised swap supplier might due to this fact substitute a token approval matching those self same parameters and have it signed with out a further gadget immediate.
The flaw couldn’t create a limiteless approval, swap to a different token, or grant permission to an arbitrary handle. An approval additionally doesn’t itself switch funds, requiring a subsequent transaction earlier than the authorised property might transfer.
Ledger stated it discovered no proof that the swap vulnerability was exploited.
The discharge historical past raises a separate query. Ledger’s data present the repair for the array-count concern was merged on Could 5 and the swap-validation correction on Could 25, months earlier than model 1.22.2 was launched. Its safety bulletins don’t clarify why these modifications had been absent from that replace.
Ledger defended its broader method by pointing to updateability as central to {hardware} pockets safety. Its safety group stated it constantly identifies vulnerabilities via inside analysis and exterior bug-bounty applications, then patches them via software program releases.
For customers, the excellence between the three vulnerabilities is vital. Model 1.22.2 fastened the command-interleaving flaw later reproduced by OneKey, whereas model 1.22.3 is required to deal with the 2 extra signing bugs disclosed Aug. 27.
Ledger recommends putting in Ethereum app 1.22.3 or later via Ledger Reside and verifying the model on the gadget. Updating the {hardware} pockets firmware alone doesn’t change the affected Ethereum software.









