Crypto wallet manufacturer Ledger is instructing Ethereum app users to update again after two signing vulnerabilities persisted in its prior security patch.

The hardware wallet company released Ethereum app version 1.22.3 on August 25, addressing flaws that could conceal operations from device review or authorize a token approval instead of an expected payment.

This update follows controversy surrounding a separate Ethereum signing flaw reproduced by rival wallet maker OneKey. Tracked as LSB-023, the issue affected older versions and allowed a compromised host to interleave commands, enabling transaction parameters to change after being displayed but before signing.

Ledger stated that OneKey demonstrated the bug against version 1.22.1, despite the company having already fixed it in Ethereum app 1.22.2, released on August 13.

“No Ledger user was hacked,” the company’s security team stated, describing the demonstration as a laboratory reproduction involving outdated software. The company reported finding no evidence of real-world exploitation.

Ledger Chief Technology Officer Charles Guillemet echoed this distinction, noting that reproducing an already-patched flaw did not constitute “hacking Ledger.”

However, version 1.22.2 did not resolve every known Ethereum app vulnerability. Two separate flaws, LSB-024 and LSB-025, remained unaddressed until the release of 1.22.3.

Two additional signing paths remained exposed

LSB-024 impacted how the Ethereum app processed arrays of operations during clear signing.

The application read the operation count using a 16-bit value but stored the remaining count in an 8-bit field. In Ledger’s proof of concept, an array containing 257 operations wrapped the counter back to one, causing the device to display only the final operation even though the signature authorized the entire batch.

Exploiting this required a compromised host and an unusually large attacker-controlled operation array. Ledger tested the scenario on a private network fork and reported no actual user losses.

Regarding the second vulnerability, LSB-025, it affected the token-payment path used by Ledger’s Exchange application during swaps.

Ledger’s app verified the token, quantity, and destination but failed to confirm that the requested action was actually a payment. Consequently, a malicious or compromised swap provider could substitute a token approval matching those same parameters and have it signed without an additional device prompt.

The flaw could not generate an unlimited approval, switch to another token, or grant permission to an arbitrary address. Furthermore, an approval does not itself transfer funds, requiring a subsequent transaction before the approved assets could move.

Ledger confirmed it found no evidence that the swap vulnerability was exploited.

The release history raises a separate question. Ledger’s records indicate the fix for the array-count issue was merged on May 5 and the swap-validation correction on May 25, months before version 1.22.2 was released. Its security bulletins do not explain why those changes were absent from that update.

Ledger defended its broader approach by emphasizing updateability as central to hardware wallet security. Its security team stated that it continuously identifies vulnerabilities through internal research and external bug-bounty programs, patching them via software releases.

For users, the distinction between the three vulnerabilities is critical. Version 1.22.2 fixed the command-interleaving flaw later reproduced by OneKey, while version 1.22.3 is required to address the two additional signing bugs disclosed on August 27.

Ledger recommends installing Ethereum app 1.22.3 or later through Ledger Live and verifying the version on the device. Updating the hardware wallet firmware alone does not replace the affected Ethereum application.

Source link

Exit mobile version