Ledger Fixes Vulnerability in Ethereum App Ahead of Potential Exploit
A vulnerability in Ledger's Ethereum app was discovered and patched before any users were affected.
The OneKey Anzen team successfully reproduced a transaction replacement attack on the wallet's version 1.22.1, but the issue was already fixed by Ledger in patch 1.22.2 released on August 13.
A race condition between the transaction display logic and the underlying buffer could cause the device to show one operation while signing another, allowing an attacker to send a new APDU command.