- ETH0%
BlockBeats News, August 28, the OneKey security team OneKey Anzen recently reproduced the Ledger vulnerability disclosed by TestMachine and found that the Ledger Ethereum app version 1.22.1 has a transaction replacement vulnerability. The attacked user's hardware screen still shows the user reviewing transaction A, but the device may actually sign transaction B that the user has never seen.
OneKey Anzen stated that the root cause of this issue is a race condition between the transaction display logic and the underlying buffer; the attack premise is that the host side has been compromised by a malicious dApp or intermediary software.
On August 22, TestMachine pointed out a security vulnerability in the well-known crypto wallet Ledger. The Ledger CTO responded the next day, stating that the vulnerability had been fixed in an update released about two weeks ago, and users just need to update the app, advising the community "not to panic." However, public information shows that the official tag for version 1.22.2 on Ledger's GitHub was not posted until August 24.
As of press time, Ledger has updated the latest developments on its official website. It stated that the issue has been fixed through application-level verification and SDK layer, and on August 21, Ledger released Ledger Secure SDK v26.6.1, with related apps rebuilt and released. Users need to update the app through Ledger Live; updating the device firmware alone is not sufficient for the fix. However, Ledger stated that there is currently no evidence that the vulnerability has been exploited.
免責事項:現在のコンテンツは第三者の視点に基づくもの、または第三者の視点からAIが直接翻訳したものです。CoinExはコンテンツの信頼性、正確性、独創性を保証するものではなく、CoinExからの投資アドバイスを構成するものではありません。暗号資産の価格変動は急激に変動します。潜在的なリスクにご注意ください。
- コインリスト価格24時間価格変動