- ETH0%
BlockBeats News, August 28, the OneKey security team OneKey Anzen recently reproduced the Ledger vulnerability disclosed by TestMachine and found that the Ledger Ethereum app version 1.22.1 has a transaction replacement vulnerability. The attacked user's hardware screen still shows the user reviewing transaction A, but the device may actually sign transaction B that the user has never seen.
OneKey Anzen stated that the root cause of this issue is a race condition between the transaction display logic and the underlying buffer; the attack premise is that the host side has been compromised by a malicious dApp or intermediary software.
On August 22, TestMachine pointed out a security vulnerability in the well-known crypto wallet Ledger. The Ledger CTO responded the next day, stating that the vulnerability had been fixed in an update released about two weeks ago, and users just need to update the app, advising the community "not to panic." However, public information shows that the official tag for version 1.22.2 on Ledger's GitHub was not posted until August 24.
As of press time, Ledger has updated the latest developments on its official website. It stated that the issue has been fixed through application-level verification and SDK layer, and on August 21, Ledger released Ledger Secure SDK v26.6.1, with related apps rebuilt and released. Users need to update the app through Ledger Live; updating the device firmware alone is not sufficient for the fix. However, Ledger stated that there is currently no evidence that the vulnerability has been exploited.
면책 조항: 현재 콘텐츠는 제3자 관점에서 제공되거나 제3자 관점에서 AI가 직접 번역한 것입니다. CoinEx는 콘텐츠의 진위성, 정확성, 독창성을 보장하지 않으며 CoinEx의 투자 조언으로 간주하지 않습니다. 암호화폐 가격은 변동성이 크므로 잠재적인 위험에 유의하시기 바랍니다.
- 코인가격24시간 변동