Ledger Denies Delay in Fixing Ethereum Signing Flaw
A recent Ethereum signing flaw discovered by security company TestMachine was already fixed by Ledger before public disclosure, according to Charles Guillemet, Ledger's Chief Technology Officer.
The issue affected certain clear signing flows in Ledger's Ethereum application and could have allowed a malicious application to replace transaction data while users reviewed Ledger device screens. However, Ledger had deployed the fix approximately two weeks prior to Guillemet's statement, he said.
Apart from the controversy surrounding the disclosure timeline, the security flaw highlights the importance of keeping firmware and applications up-to-date to protect against vulnerabilities. Users should update their Ledger Wallet software, device firmware, and installed Ethereum application to ensure protection against this specific issue.