Ledger Ethereum App Flaws Exposed: Users Warned to Verify Transactions
Three vulnerabilities were discovered in Ledger's Ethereum app that could have allowed an attacker to sign a different transaction than what was shown on screen. The flaws, which were patched with version 1.22.2 of the app, were found by Ledger's security team using AI-based automated research tools.
The main problem involved the way the device communicated with the computer, allowing a compromised PC to fire off new commands while the user confirmed a legitimate transaction. This resulted in the display showing one transaction, but the chip signing another. In the worst-case scenario, an attacker could have convinced the user to authorize unlimited spending to their address.
The bugs were discovered after TestMachine's AI scanner Azimuth reportedly spotted the flaw in an autonomous scan, and Anzen team at OneKey reconstructed the substitution attack in the lab against version 1.22.1. However, Ledger pushed back on the alarmist reading, stating that anyone running the latest version was already protected.