Ledger's Delayed Disclosure Sparks Debate Over Vulnerability Timing
Hardware wallet maker Ledger faced criticism for its delayed disclosure of a security vulnerability in the Ethereum app, which was patched two weeks prior to the announcement.
The issue, discovered by Ledger's internal security research team, affected the clear-signing process of the Ethereum app, allowing users to review transaction details before signing a blockchain transaction.
According to Ledger CTO Charles Guillemet, users who keep their Ledger device firmware and related applications up to date are protected from this vulnerability, which is confined to the Ethereum app and does not affect the Ledger device hardware itself.
The crux of the matter is the timing of disclosure, with some arguing that a 'silent patch' followed by belated disclosure can leave users unaware of potential risks before updating their software.