買幣
行情
現貨
合約
理財
活動
更多
reward-center新手專區
信息首頁快訊詳情
OneKey Security Team Reproduces Ledger Vulnerability, Affected Users Experience Transaction Approval Mismatch
  • ETH0%

BlockBeats News, August 28, the OneKey security team OneKey Anzen recently reproduced the Ledger vulnerability disclosed by TestMachine and found that the Ledger Ethereum app version 1.22.1 has a transaction replacement vulnerability. The attacked user's hardware screen still shows the user reviewing transaction A, but the device may actually sign transaction B that the user has never seen.

OneKey Anzen stated that the root cause of this issue is a race condition between the transaction display logic and the underlying buffer; the attack premise is that the host side has been compromised by a malicious dApp or intermediary software.

On August 22, TestMachine pointed out a security vulnerability in the well-known crypto wallet Ledger. The Ledger CTO responded the next day, stating that the vulnerability had been fixed in an update released about two weeks ago, and users just need to update the app, advising the community "not to panic." However, public information shows that the official tag for version 1.22.2 on Ledger's GitHub was not posted until August 24.

As of press time, Ledger has updated the latest developments on its official website. It stated that the issue has been fixed through application-level verification and SDK layer, and on August 21, Ledger released Ledger Secure SDK v26.6.1, with related apps rebuilt and released. Users need to update the app through Ledger Live; updating the device firmware alone is not sufficient for the fix. However, Ledger stated that there is currently no evidence that the vulnerability has been exploited.

來源:BlockBeats

免責聲明:當前內容均來自第三方觀點或由AI直接翻譯第三方觀點,CoinEx不保證內容的真實性、準確性和原創性,不構成CoinEx相關的任何投資建議。數字資產價格波動劇烈,請注意潛在風險。

熱搜榜
  • 幣種
    價格
    24H漲跌