Ledger says Ethereum signing flaw was already fixed
7 Articles
7 Articles
What to remember: Ledger indicates that he has corrected a flaw affecting certain clear signature streams on his Ethereum application. The security company TestMachine claims that a malicious application could substitute a transaction. No verified theft of funds was linked to this vulnerability on 24 August. Ledger claims to have corrected a vulnerability affecting certain clear signature streams of his Ethereum application before another securi…
A vulnerability affecting Ledger's Ethereum application sparked controversy after its disclosure by TestMachine. Ledger however ensures that the flaw had already been identified internally and corrected several days earlier. The Ledger article denies a critical flaw on his Ethereum app appeared first on Cryptoast.
Ledger Fixes Ethereum App Signing Bug Affecting Clear Signing
Ledger’s Ethereum app version 1.22.2, released August 12, patched a bug in how the app handled transaction review, according to the project’s own public changelog. The bug could have let a malicious application swap the transaction a user was...
Ledger Patches Ethereum Signing Flaw Before Researchers Disclose It
Ledger has patched a vulnerability in its Ethereum hardware-wallet app that could allow a malicious dApp to replace a transaction during the approval process while the device continued showing users the transaction they originally reviewed. Security firm TestMachine disclosed the signature-substitution flaw on August 21 after reproducing it on Ledger hardware. Ledger had already shipped Ethereum app version 1.22.2 on August 12, with its release …
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









