OneKey disclosed a vulnerability in Ledger's Ethereum app that allowed transaction signing mismatches, but Ledger says the flaw was already patched before exploit.
Security & Exploits ·
OneKey's security team reproduced a transaction-replacement vulnerability in Ledger's Ethereum app version 1.22.1 that could display one transaction while signing another, requiring an attacker to first control communications between the device and its host. Ledger said the flaw was patched in Ethereum app version 1.22.2 on August 13, before OneKey's public demonstration, and the company has found no evidence of exploitation outside the laboratory. The vulnerability required malware, a compromised wallet app, or a hostile website to exploit, and Ledger recommends users install Ethereum app version 1.22.3 or later.