Ledger Reassures Users of Patched Vulnerability, Urges Updates
Charles Guillemet, Ledger's Chief Technology Officer, has moved to reassure users about a recent security vulnerability in their Ethereum app. The flaw, which affected the clear-signing process, could have allowed malicious actors to trick users into approving fraudulent transactions. However, Guillemet confirmed that the issue was patched two weeks ago and emphasized that updated users are already protected.
The vulnerability, which was identified in parts of the app's clear-signing feature, potentially left a window for attackers to manipulate what users see on their device screens. The clear-signing process is a critical security feature in hardware wallets that displays transaction details in a human-readable format, allowing users to verify and approve transactions with confidence.
Guillemet stressed the importance of regular updates in maintaining the security of cryptocurrency hardware wallets. He urged users to update their Ledger firmware and Ethereum app to the latest versions via Ledger Live, as doing so would ensure they are protected from the vulnerability.