Ledger has addressed a security vulnerability in its Ethereum application, fixing the issue before it became public, according to Chief Technology Officer Charles Guillemet. The update was re
Ledger has addressed a security vulnerability in its Ethereum application, fixing the issue before it became public, according to Chief Technology Officer Charles Guillemet. The update was released approximately two weeks ahead of any disclosure by external researchers.
Clear signing feature and potential risks
Ledger, a leading provider of hardware crypto wallets, uses a clear signing feature in its Ethereum application that enables users to view transaction details such as amounts, addresses, and specific smart contract interactions in plain text directly on their device. This approach enhances transparency for users and aims to reduce approval errors that could occur when interpreting raw hexadecimal data.
A security assessment by TestMachine, a cybersecurity firm, identified a path for malicious apps to exploit the clear signing process. According to TestMachine, its in-house tool Azimuth found a method whereby an attacker could issue a secondary hidden command to Ledger’s Ethereum app while the user was still considering the initial transaction displayed on the device. This could potentially let an attacker swap a legitimate small transaction for a more sweeping token approval, with the device only reflecting the benign transaction the user expected to authorize.
TestMachine stated that communication between the connected application and Ledger’s device facilitated this exploit. The firm did not suggest widespread exploitation but outlined the theoretical risk in scenarios where users relied solely on screen information without additional verification.
Mini dictionary: TestMachine is a cybersecurity company focused on blockchain and smart contract security, while Azimuth is its proprietary security research tool used to identify vulnerabilities in crypto wallets and related software.
TestMachine described a situation where a user might see one action on their Ledger device while a hidden process initiates a separate, more dangerous transaction. The company reported it verified its findings and declined a bounty reward from Ledger.
Disagreement over disclosure and timelines
The vulnerability was first detected internally by Ledger’s security division, known as Ledger Donjon, which used AI-based analysis tools to identify the flaw. Guillemet confirmed the patch was deployed well before the security report was published, and stated that the fix was already public when TestMachine made contact with the company’s bounty program.
TestMachine, however, said it tested the vulnerability using a Ledger Flex device and noted that shared software code could affect other Ledger wallet models, including the Nano X, Nano S Plus, Stax, and Apex. Despite concerns about broader device exposure, there have been no verified incidents of funds lost due to this specific flaw.
Ledger’s public code repository documents several security updates from August, primarily aimed at refining signing states and message management. The exact update that resolved TestMachine’s reported issue remains undisclosed.
Guillemet argued that TestMachine presented its findings only after a fix was implemented, and accused the researchers of creating unnecessary fear by not first confirming the patch’s presence with Ledger’s bounty team.
TestMachine maintains it followed responsible disclosure practices and has yet to reconcile its timeline with Ledger’s public statements.
Mini dictionary: Ledger Donjon is Ledger’s internal security team, specializing in identifying and mitigating vulnerabilities within Ledger’s hardware wallet ecosystem.
User guidance and previous incidents
Ledger urged all users to update their device’s firmware, Ethereum application, and companion software to ensure full security coverage. The company emphasized that updating only the desktop or mobile interface does not provide protection if device firmware or individual apps remain outdated.
In addition, Ledger advised users to carefully verify transaction details on their device screen before granting approval, as so-called blind signing of smart contract actions can leave users exposed to malicious code that is not clearly presented.
Ledger clarified that the recent bug is distinct from a previous vulnerability related to Zilliqa that resulted in exposed private keys and affected wallets secured via the Zilliqa Ledger app. There is currently no fund recovery or compensation plan related to the Ethereum signing bug, and no formal advisory listing specific affected versions has been released so far.
Device ModelAffected by Reported BugPatch StatusFlexTested, potentially affectedPatchedNano XPotentially affectedPatchedNano S PlusPotentially affectedPatchedStaxPotentially affectedPatchedApexPotentially affectedPatched
The post Ledger patches Ethereum app signing bug before TestMachine disclosure appeared first on COINTURK NEWS.