Ledger Fixes Ethereum App Vulnerability After Public Disclosure
Security firm Ledger has fixed a vulnerability in its Ethereum app that allowed users to unknowingly sign different transactions than those displayed. The issue, which was discovered in version 1.22.2 of the app, was resolved on August 12. However, controversy arose when a security researcher publicly disclosed the flaw without giving Ledger prior notice.
According to Ledger, the issue was fixed before the public disclosure and users were urged to update their firmware and verify transactions carefully. The company also stated that no funds were reported stolen due to this vulnerability.