Crypto pockets maker Ledger is urging its Ethereum app customers to replace once more after two signing flaws remained in its earlier safety launch.
The hardware-wallet maker printed Ethereum app model 1.22.3 on Aug. 25, closing vulnerabilities that would cover operations from a tool evaluation or authorize a token approval rather than an anticipated fee.
The replace follows controversy over a separate Ethereum signing flaw reproduced by rival pockets maker OneKey. That subject, tracked as LSB-023, affected older variations and allowed a compromised host to interleave instructions in order that transaction parameters may change after being displayed however earlier than signing.
Ledger stated OneKey demonstrated the bug in opposition to model 1.22.1 after the corporate had already fastened it in Ethereum app 1.22.2, launched Aug. 13.
“No Ledger person was hacked,” Ledger’s safety crew said, describing the demonstration as a laboratory replica involving outdated software program. The corporate stated it had discovered no proof of exploitation within the wild.
Ledger Chief Technology Officer Charles Guillemet made the identical distinction, saying reproducing an already-patched flaw didn’t quantity to “hacking Ledger.”
Model 1.22.2, nonetheless, didn’t shut each identified Ethereum-app vulnerability on Ledger. As a substitute, two separate flaws, LSB-024 and LSB-025, remained till the discharge of 1.22.3.
Two further signing paths remained uncovered
LSB-024 affected how the Ethereum app processed arrays of operations throughout clear signing.
The app learn the variety of operations utilizing a 16-bit worth however saved the remaining rely in an 8-bit area. In Ledger’s proof of idea, an array containing 257 operations wrapped the counter again to 1, inflicting the system to show solely the ultimate operation though its signature approved all the batch.
Exploitation required a compromised host and an unusually massive attacker-controlled operation array. Ledger examined the situation on a personal community fork and reported no real-user losses.
The second vulnerability, LSB-025, affected the token-payment path utilized by Ledger’s Change software throughout swaps.

Ledger’s app checked the token, amount, and vacation spot however didn’t confirm that the requested motion was really a fee. A malicious or compromised swap supplier may due to this fact substitute a token approval matching those self same parameters and have it signed with out a further system immediate.
The flaw couldn’t create an infinite approval, change to a different token, or grant permission to an arbitrary handle. An approval additionally doesn’t itself switch funds, requiring a subsequent transaction earlier than the permitted belongings may transfer.
Ledger stated it discovered no proof that the swap vulnerability was exploited.
The discharge historical past raises a separate query. Ledger’s data present the repair for the array-count subject was merged on Could 5 and the swap-validation correction on Could 25, months earlier than model 1.22.2 was launched. Its safety bulletins don’t clarify why these modifications have been absent from that replace.
Ledger defended its broader strategy by pointing to updateability as central to hardware wallet security. Its safety crew stated it constantly identifies vulnerabilities by inside analysis and exterior bug-bounty applications, then patches them by software program releases.
For customers, the excellence between the three vulnerabilities is vital. Model 1.22.2 fastened the command-interleaving flaw later reproduced by OneKey, whereas model 1.22.3 is required to handle the 2 further signing bugs disclosed Aug. 27.
Ledger recommends putting in Ethereum app 1.22.3 or later by Ledger Stay and verifying the model on the system. Updating the hardware wallet firmware alone doesn’t substitute the affected Ethereum software.
