Skip to main content
Ledger says Ethereum flaw fixed in 1.22.2
Image for illustrative purposes only. Not a real photo.

Ledger says Ethereum flaw fixed in 1.22.2

Share
  • Ledger says it was not hacked after researchers reproduced a vulnerability in an older Ethereum app.
  • The flaw could have allowed an attacker to replace transaction details before a user signed them.
  • Ledger says the issue was fixed on August 13, with no evidence of exploitation outside a lab.

Ledger says it was not hacked after researchers reproduced a vulnerability in its outdated Ethereum app.

Researchers from rival wallet maker OneKey recreated the issue using Ethereum app version 1.22.1 in a laboratory.

The flaw could allow an attacker to show one transaction while replacing it with another before the user signed it.

OneKey said the issue involved a race condition between transaction display logic and the transaction data awaiting approval.

Ledger Chief Technology Officer Charles Guillemet said the flaw had already been fixed in version 1.22.2, released on August 13.

Ledger said an attacker would first need control over communications between the device and host through malware, a compromised wallet app or hostile website.

Ledger said it found no evidence of attacks in the wild and advised users to update the Ethereum app to version 1.22.3 or later.

Frequently asked questions