Ledger's Ethereum App Flaw Sparks Disclosure Dispute
A recent disclosure by security firm TestMachine has brought to light a clear-signing flaw in Ledger's Ethereum app. The issue, which was discovered and validated using an AI-powered vulnerability scanner, allows malicious applications to send competing commands while a user is reviewing a legitimate transaction.
The flaw could potentially be exploited to replace a limited transaction with a broader token approval. TestMachine said its AI scanner, Azimuth, found the issue during an autonomous scan on a Ledger Flex device. Because of shared code, other devices such as Nano X, Nano S Plus, Stax, and Apex may also be affected.
Ledger CTO Charles Guillemet disputed TestMachine's account, claiming that Ledger's internal security research team had independently identified the issue two weeks before it was publicly disclosed. Guillemet said that the fix had already been deployed, but TestMachine disagreed, stating that they had shared and verified their finding with Ledger prior to publication.
The lack of a detailed technical advisory or patched release identifier from Ledger has raised concerns among users. To protect themselves, users are advised to keep their firmware and apps updated and check the device's own app store for updates to the Ethereum app.