Ledger Vulnerability Replicated as Trezor and Ledger Push for Safer Bug Disclosure
The Ledger Ethereum app vulnerability has been replicated by OneKey's Anzen security team. The team successfully reproduced a transaction replacement attack against Ledger Ethereum app version 1.22.1. This allowed a race condition that replaced transactions before signing.
Ledger had previously patched the vulnerability, but this new discovery raises questions about the effectiveness of their patch.
Trezor and Ledger have urged safer bug disclosure practices to prevent similar vulnerabilities in the future.