Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Ledger Patches Ethereum App Bug That Could Allow Transaction Substitution

Ledger has released Ethereum app version 1.22.2 to address a signing-state flaw that could potentially lead to transaction data substitution during the review process.
2 weeks ago 39 views
Ledger Patches Ethereum App Bug That Could Allow Transaction Substitution

Ledger has updated its Ethereum application to version 1.22.2 to patch a vulnerability that could allow a connected malicious decentralized application (dApp) or host to initiate a second signing command while a transaction was still under active review.

According to security company TestMachine, which detailed the issue on Aug. 22, the flaw could permit a dApp with WebHID access to replace transaction data held in memory without prompting a new review screen. This meant the original transaction details could remain visible on the physical device while a signature was generated for different, substituted data upon user approval.

Public validation of this specific substitution path was demonstrated on the Ledger Flex model. TestMachine asserted that shared code extended the issue to other models including the Nano X, Nano S Plus, Stax, and Apex, which are listed alongside the Flex in the app's build targets. However, the earliest affected app release remains undisclosed.

Ledger's code history indicates that version 1.22.2 introduces two primary safeguards. The update closes the vulnerability by refusing new signing sessions during an active review and by rejecting approval callbacks if the state no longer matches the expected signing condition. Ledger's changelog lists the release date for version 1.22.2 as Aug. 12, with a signed tag on GitHub on Aug. 13.

Ledger CTO Charles Guillemet stated on Aug. 23 that Ledger Donjon had discovered a bug in certain clear signing flows and deployed the fix roughly two weeks prior, noting that Donjon found the issue before TestMachine contacted the bounty program. TestMachine stated that its Azimuth system discovered the finding and that it was shared and verified with Ledger.

There have been no reported instances of confirmed in-the-wild exploitation, lost funds, or private-key extraction related to this issue. Users are advised to ensure they have Ethereum app version 1.22.2 installed and to keep their device firmware, apps, and client software updated.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.