Ledger Ethereum App Vulnerability Exposed: Update Immediately
A critical vulnerability in Ledger's Ethereum app was discovered by an AI-powered security research team on August 26. The bug, found using AI tools, could have allowed hackers to drain a user's wallet during a single transaction.
The issue was identified as a flaw in certain clear signing flows that would allow malicious decentralized applications (DApps) to swap harmless transfers for unlimited token approvals, granting backdoor access to all ERC-20 tokens on users' Ledger hardware wallets.
Ledger patched the vulnerability quietly on August 12 with version 1.22.2, and users who keep their apps up-to-date are protected. However, those who have not updated remain vulnerable, and the company urged all its customers to update to the latest version.