Ledger Fixes Security Flaw in Ethereum App Signing Process
Ledger has fixed a security flaw in its Ethereum app's signing process.
A vulnerability was found in some signing flows that use clear signing, which allows users to review transaction details before signing a blockchain transaction.
The issue was discovered by Ledger's security research team, Ledger Donjon, and patched about two weeks ago, according to Charles Guillemet, the company's Chief Technology Officer.
User devices are protected if they have been updated to the latest versions of their firmware and related applications.
Guillemet also criticized an external security firm for disclosing the vulnerability after Ledger had already completed the patch rollout. He stated that this firm suggested the issue had not been resolved when it was, in fact, fixed.