Crypto pockets maker Ledger is urging its Ethereum app customers to replace once more after two signing flaws remained in its earlier safety launch.
The hardware-wallet maker printed Ethereum app model 1.22.3 on Aug. 25, closing vulnerabilities that might disguise operations from a tool evaluation or authorize a token approval instead of an anticipated fee.
The replace follows controversy over a separate Ethereum signing flaw reproduced by rival pockets maker OneKey. That situation, tracked as LSB-023, affected older variations and allowed a compromised host to interleave instructions in order that transaction parameters might change after being displayed however earlier than signing.
Ledger mentioned OneKey demonstrated the bug towards model 1.22.1 after the corporate had already mounted it in Ethereum app 1.22.2, launched Aug. 13.
“No Ledger person was hacked,” Ledger’s safety workforce said, describing the demonstration as a laboratory copy involving outdated software program. The corporate mentioned it had discovered no proof of exploitation within the wild.
Ledger Chief Technology Officer Charles Guillemet made the identical distinction, saying reproducing an already-patched flaw didn’t quantity to “hacking Ledger.”
Model 1.22.2, nonetheless, didn’t shut each identified Ethereum-app vulnerability on Ledger. As an alternative, two separate flaws, LSB-024 and LSB-025, remained till the discharge of 1.22.3.
Two extra signing paths remained uncovered
LSB-024 affected how the Ethereum app processed arrays of operations throughout clear signing.
The app learn the variety of operations utilizing a 16-bit worth however saved the remaining depend in an 8-bit discipline. In Ledger’s proof of idea, an array containing 257 operations wrapped the counter again to at least one, inflicting the gadget to show solely the ultimate operation although its signature approved your entire batch.
Exploitation required a compromised host and an unusually giant attacker-controlled operation array. Ledger examined the state of affairs on a non-public community fork and reported no real-user losses.
The second vulnerability, LSB-025, affected the token-payment path utilized by Ledger’s Trade software throughout swaps.

Ledger’s app checked the token, amount, and vacation spot however didn’t confirm that the requested motion was truly a fee. A malicious or compromised swap supplier might subsequently substitute a token approval matching those self same parameters and have it signed with out a further gadget immediate.
The flaw couldn’t create an infinite approval, swap to a different token, or grant permission to an arbitrary tackle. An approval additionally doesn’t itself switch funds, requiring a subsequent transaction earlier than the permitted belongings might transfer.
Ledger mentioned it discovered no proof that the swap vulnerability was exploited.
The discharge historical past raises a separate query. Ledger’s information present the repair for the array-count situation was merged on Might 5 and the swap-validation correction on Might 25, months earlier than model 1.22.2 was launched. Its safety bulletins don’t clarify why these adjustments had been absent from that replace.
Ledger defended its broader method by pointing to updateability as central to hardware wallet security. Its safety workforce mentioned it constantly identifies vulnerabilities by inner analysis and exterior bug-bounty packages, then patches them by software program releases.
For customers, the excellence between the three vulnerabilities is necessary. Model 1.22.2 mounted the command-interleaving flaw later reproduced by OneKey, whereas model 1.22.3 is required to handle the 2 extra signing bugs disclosed Aug. 27.
Ledger recommends putting in Ethereum app 1.22.3 or later by Ledger Reside and verifying the model on the gadget. Updating the hardware wallet firmware alone doesn’t exchange the affected Ethereum software.
