Ledger Fixes Ethereum App Vulnerability, Critics Raise Disclosure Concerns
Hardware wallet vendor Ledger has patched a vulnerability in its Ethereum app that could have allowed malicious dApps to replace transactions during approval. Security firm TestMachine revealed the signature-substitution flaw, which affected the command flow between connected dApps and Ledger's Ethereum application.
The issue, discovered on August 21, allowed a malicious application with direct device access through WebHID to interfere while a transaction review remained open, replacing the signing context before user approval. TestMachine demonstrated this by substituting a benign ETH transfer with a token approval, creating a path for users to authorize something different from the original transaction displayed.
Ledger CTO Charles Guillemet stated that the company's Donjon security team had already identified and fixed the bug roughly two weeks before TestMachine published its findings, using AI-assisted security tools. Guillemet also criticized the disclosure process, saying TestMachine contacted Ledger's bounty program after the patch had shipped and then published their findings without completing the normal responsible-disclosure process.