Ledger Fixes Vulnerability in Ethereum App with Firmware Update
Ledger, a well-known hardware wallet manufacturer, has resolved a vulnerability in its Ethereum application. The bug was identified by the company's CTO, Charles Guillemet, and was related to the handling of streams in APDU commands.
According to Guillemet, the issue could have allowed a malicious smart contract to alter transaction data during signing, potentially leading to unauthorized access or transactions. However, users with up-to-date firmware and application patches are fully protected.
The fix has been deployed in version 1.22.2 of the Ethereum app. Guillemet criticized the public disclosure of the issue, stating that an external company sought a reward after the fix was released without discussing the case with the program team.