• About
  • FAQ
  • Earn Bitcoin while Surfing the net
  • Buy & Sell Crypto on Paxful
Newsletter
Approx Foundation
  • Home
    • Home – Layout 1
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
Approx Foundation
No Result
View All Result
Home Regulation

Ledger patched an Ethereum app bug that could show one transaction and sign another

Moussa by Moussa
August 25, 2026
in Regulation
0
Ledger patched an Ethereum app bug that could show one transaction and sign another
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Ledger users should update the Ethereum app to version 1.22.2 after official code changes showed that a malicious dApp or other connected host could start a second signing command while a transaction was still under review.

In the path described by security company TestMachine, pressing approve could return a signature for substituted data instead of the transaction shown on the device.

TestMachine said on Aug. 22 that the attack required a dApp with WebHID access. The group said a second command could replace the transaction held in memory without opening a new review, leaving the original details on screen while the device signed the replacement.

It said the behavior was validated on Ledger Flex.

Ledger’s code history shows one official fix commit saying new signing commands could tear down an active review before returning an error. Another added state checks because approval callbacks previously signed without confirming that the app remained in the expected signing state.

Version 1.22.2 closes that documented path by refusing a new signing session during an active review and rejecting an approval callback when the state no longer matches. The reviewed sources establish a code-level fix for those entry and callback defects.

Flowchart of the researcher-described Ledger Ethereum signing race and the two safeguards added in app version 1.22.2Flowchart of the researcher-described Ledger Ethereum signing race and the two safeguards added in app version 1.22.2
Diagram showing the signing-state race described for Ledger’s Ethereum app and the safeguards added in version 1.22.2.

TestMachine asserted that shared code extended the issue to Nano X, Nano S Plus, Stax, and Apex, and the tagged app manifest lists those models alongside Flex as build targets.

The Daily Brief

The signal, before the noise.

Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.

One email. Everything that matters.

Free to join. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re on the list. Your next Daily Brief is on its way.

Ledger’s release comparison starts from version 1.22.1, while the earliest affected app release remains undisclosed.

Related Reading

A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds

Ledger’s changelog dates 1.22.2 to Aug. 12, GitHub shows the signed tag on Aug. 13, and TestMachine said on Aug. 22 that the fix was not yet released.

Ledger CTO Charles Guillemet said on Aug. 23 that Ledger Donjon had found a bug in “certain clear signing flows” and deployed the fix about two weeks earlier. The sources leave open whether TestMachine was referring to distribution through Ledger Wallet.

Guillemet said Donjon found the bug before TestMachine contacted Ledger’s bounty program, while TestMachine said its Azimuth system found the issue and that it shared and verified the finding with Ledger.

Users should confirm that Ethereum app 1.22.2 is installed. Guillemet also advised keeping device firmware, apps, and client software current, although the public sources give no firmware minimum specific to this flaw.

They report no confirmed in-the-wild exploitation, lost funds, or private-key extraction.

The issue is separate from the native Zilliqa Ledger app flaw involving Schnorr nonce leakage and the 2023 Connect Kit compromise, which involved a malicious JavaScript library and reported losses.

Related articles

Arbitrum pauses new Stylus activations over AI-assisted attack risks

Arbitrum pauses new Stylus activations over AI-assisted attack risks

October 3, 2026
Introducing zkAPI: private usage credits for any API

Introducing zkAPI: private usage credits for any API

October 1, 2026



Source link

Share76Tweet47

Related Posts

Arbitrum pauses new Stylus activations over AI-assisted attack risks

Arbitrum pauses new Stylus activations over AI-assisted attack risks

by Moussa
October 3, 2026
0

Arbitrum's Security Council temporarily blocked new Stylus contract activations on Arbitrum One and Nova in an October 2 emergency action,...

Introducing zkAPI: private usage credits for any API

Introducing zkAPI: private usage credits for any API

by Moussa
October 1, 2026
0

tl;dr: zkAPI lets you pay for a metered API without being known. Deposit credits into an Ethereum vault once, then...

MetaMask security scare pushes Ethereum validator exits to a nine-month high

MetaMask security scare pushes Ethereum validator exits to a nine-month high

by Moussa
October 1, 2026
0

MetaMask is pulling thousands of Ethereum validators after a security breach redirected rewards, creating a network-wide backlog for stakers trying...

Ethereum is preparing a 200 million gas push as its Layer 1 scaling strategy accelerates

Ethereum is preparing a 200 million gas push as its Layer 1 scaling strategy accelerates

by Moussa
October 1, 2026
0

Ethereum validators face a configuration choice next week that could determine how aggressively the network tests its next major scaling...

Aave’s lending plan could lose money without defaults

Aave’s lending plan could lose money without defaults

by Moussa
September 30, 2026
0

Aave’s proposed institutional lending business would put crypto collateral on both sides of the financing chain. Institutions would pledge Bitcoin...

Load More

youssufi.com

sephina.com

[vc_row full_width="stretch_row" parallax="content-moving" vc_row_background="" background_repeat="no-repeat" background_position="center center" footer_scheme="dark" css=".vc_custom_1517813231908{padding-top: 60px !important;padding-bottom: 30px !important;background-color: #191818 !important;background-position: center;background-repeat: no-repeat !important;background-size: cover !important;}" footer_widget_title_color="#fcbf46" footer_button_bg="#fcb11e"][vc_column width="1/4"]

We bring you the latest in Crypto News

[/vc_column][vc_column width="1/4"][vc_wp_categories]
[/vc_column][vc_column width="1/4"][vc_wp_tagcloud taxonomy="post_tag"][/vc_column][vc_column width="1/4"]

Newsletter

[vc_raw_html]JTNDcCUzRSUzQ2RpdiUyMGNsYXNzJTNEJTIydG5wJTIwdG5wLXN1YnNjcmlwdGlvbiUyMiUzRSUwQSUzQ2Zvcm0lMjBtZXRob2QlM0QlMjJwb3N0JTIyJTIwYWN0aW9uJTNEJTIyaHR0cHMlM0ElMkYlMkZhcHByb3gub3JnJTJGJTNGbmElM0RzJTIyJTNFJTBBJTBBJTNDaW5wdXQlMjB0eXBlJTNEJTIyaGlkZGVuJTIyJTIwbmFtZSUzRCUyMm5sYW5nJTIyJTIwdmFsdWUlM0QlMjIlMjIlM0UlM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1maXJzdG5hbWUlMjIlM0UlM0NsYWJlbCUyMGZvciUzRCUyMnRucC0xJTIyJTNFRmlyc3QlMjBuYW1lJTIwb3IlMjBmdWxsJTIwbmFtZSUzQyUyRmxhYmVsJTNFJTBBJTNDaW5wdXQlMjBjbGFzcyUzRCUyMnRucC1uYW1lJTIyJTIwdHlwZSUzRCUyMnRleHQlMjIlMjBuYW1lJTNEJTIybm4lMjIlMjBpZCUzRCUyMnRucC0xJTIyJTIwdmFsdWUlM0QlMjIlMjIlM0UlM0MlMkZkaXYlM0UlMEElM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1lbWFpbCUyMiUzRSUzQ2xhYmVsJTIwZm9yJTNEJTIydG5wLTIlMjIlM0VFbWFpbCUzQyUyRmxhYmVsJTNFJTBBJTNDaW5wdXQlMjBjbGFzcyUzRCUyMnRucC1lbWFpbCUyMiUyMHR5cGUlM0QlMjJlbWFpbCUyMiUyMG5hbWUlM0QlMjJuZSUyMiUyMGlkJTNEJTIydG5wLTIlMjIlMjB2YWx1ZSUzRCUyMiUyMiUyMHJlcXVpcmVkJTNFJTNDJTJGZGl2JTNFJTBBJTNDZGl2JTIwY2xhc3MlM0QlMjJ0bnAtZmllbGQlMjB0bnAtcHJpdmFjeS1maWVsZCUyMiUzRSUzQ2xhYmVsJTNFJTNDaW5wdXQlMjB0eXBlJTNEJTIyY2hlY2tib3glMjIlMjBuYW1lJTNEJTIybnklMjIlMjByZXF1aXJlZCUyMGNsYXNzJTNEJTIydG5wLXByaXZhY3klMjIlM0UlQzIlQTBCeSUyMGNvbnRpbnVpbmclMkMlMjB5b3UlMjBhY2NlcHQlMjB0aGUlMjBwcml2YWN5JTIwcG9saWN5JTNDJTJGbGFiZWwlM0UlM0MlMkZkaXYlM0UlM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1idXR0b24lMjIlM0UlM0NpbnB1dCUyMGNsYXNzJTNEJTIydG5wLXN1Ym1pdCUyMiUyMHR5cGUlM0QlMjJzdWJtaXQlMjIlMjB2YWx1ZSUzRCUyMlN1YnNjcmliZSUyMiUyMCUzRSUwQSUzQyUyRmRpdiUzRSUwQSUzQyUyRmZvcm0lM0UlMEElM0MlMkZkaXYlM0UlM0NiciUyRiUzRSUzQyUyRnAlM0U=[/vc_raw_html][/vc_column][/vc_row]
No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© 2024 APPROX FOUNDATION - The Crypto Currency News