• About
  • Privacy Poilicy
  • Disclaimer
  • Contact
CoinInsight
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
CoinInsight
No Result
View All Result
Home Ethereum

Ledger patched critical signing bugs months after writing the fixes

Coininsight by Coininsight
August 29, 2026
in Ethereum
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

Glamsterdam Repricing Impact for Smart Contract Developers

August 27, 2026

Ethereum EIP-8148 draft: custom sweep thresholds

August 27, 2026


Crypto wallet maker Ledger is urging its Ethereum app users to update again after two signing flaws remained in its previous security release.

The hardware-wallet maker published Ethereum app version 1.22.3 on Aug. 25, closing vulnerabilities that could hide operations from a device review or authorize a token approval in place of an expected payment.

The update follows controversy over a separate Ethereum signing flaw reproduced by rival wallet maker OneKey. That issue, tracked as LSB-023, affected older versions and allowed a compromised host to interleave commands so that transaction parameters could change after being displayed but before signing.

Ledger said OneKey demonstrated the bug against version 1.22.1 after the company had already fixed it in Ethereum app 1.22.2, released Aug. 13.

Related Reading

Ledger patched an Ethereum app bug that could show one transaction and sign another

“No Ledger user was hacked,” Ledger’s security team said, describing the demonstration as a laboratory reproduction involving outdated software. The company said it had found no evidence of exploitation in the wild.

Ledger Chief Technology Officer Charles Guillemet made the same distinction, saying reproducing an already-patched flaw did not amount to “hacking Ledger.”

Version 1.22.2, however, did not close every known Ethereum-app vulnerability on Ledger. Instead, two separate flaws, LSB-024 and LSB-025, remained until the release of 1.22.3.

Two additional signing paths remained exposed

LSB-024 affected how the Ethereum app processed arrays of operations during clear signing.

The app read the number of operations using a 16-bit value but stored the remaining count in an 8-bit field. In Ledger’s proof of concept, an array containing 257 operations wrapped the counter back to one, causing the device to display only the final operation even though its signature authorized the entire batch.

Exploitation required a compromised host and an unusually large attacker-controlled operation array. Ledger tested the scenario on a private network fork and reported no real-user losses.

The Daily Brief

The signal, before the noise.

Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.

One email. Everything that matters.

Free to join. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re on the list. Your next Daily Brief is on its way.

The second vulnerability, LSB-025, affected the token-payment path used by Ledger’s Exchange application during swaps.

Comparison of Ledger Ethereum app flaws LSB-024 and LSB-025, their affected versions, narrow trigger conditions, and the update to version 1.22.3Comparison of Ledger Ethereum app flaws LSB-024 and LSB-025, their affected versions, narrow trigger conditions, and the update to version 1.22.3

Ledger’s app checked the token, quantity, and destination but did not verify that the requested action was actually a payment. A malicious or compromised swap provider could therefore substitute a token approval matching those same parameters and have it signed without an additional device prompt.

The flaw could not create an unlimited approval, switch to another token, or grant permission to an arbitrary address. An approval also does not itself transfer funds, requiring a subsequent transaction before the approved assets could move.

Ledger said it found no evidence that the swap vulnerability was exploited.

The release history raises a separate question. Ledger’s records show the fix for the array-count issue was merged on May 5 and the swap-validation correction on May 25, months before version 1.22.2 was released. Its security bulletins do not explain why those changes were absent from that update.

Ledger defended its broader approach by pointing to updateability as central to hardware wallet security. Its security team said it continuously identifies vulnerabilities through internal research and external bug-bounty programs, then patches them through software releases.

For users, the distinction between the three vulnerabilities is important. Version 1.22.2 fixed the command-interleaving flaw later reproduced by OneKey, while version 1.22.3 is required to address the two additional signing bugs disclosed Aug. 27.

Ledger recommends installing Ethereum app 1.22.3 or later through Ledger Live and verifying the version on the device. Updating the hardware wallet firmware alone does not replace the affected Ethereum application.

Share76Tweet47

Related Posts

Glamsterdam Repricing Impact for Smart Contract Developers

by Coininsight
August 27, 2026
0

TL;DR: The upcoming Glamsterdam upgrade includes a set of gas repricings. EIP-8037 and EIP-8038 (both scheduled for inclusion) adjust the...

Ethereum EIP-8148 draft: custom sweep thresholds

by Coininsight
August 27, 2026
0

Ethereum is considering a change that would let compounding validators set how much ETH should remain on a validator before...

The Long(er) road to Devcon

by Coininsight
August 25, 2026
0

Friends, In the time since the last Devcon announcement, the state of the Ethereum ecosystem has been electric. We’ve realized...

FETH and FSOL staking: Fidelity redemption risks explained

by Coininsight
August 25, 2026
0

Fidelity’s FETH and FSOL staking plans give its Ethereum and Solana exchange-traded products authority to stake up to 100% of...

Ethereum researchers are racing to close a zkEVM security gap before December

by Coininsight
August 23, 2026
0

Ethereum’s better.codes contest now measures a cryptographic proof gap that researchers can attack from both sides.At 15:44:47 UTC on Aug....

Load More
  • Trending
  • Comments
  • Latest
What’s Actually Going On With Ripple’s Blockchain?

What’s Actually Going On With Ripple’s Blockchain?

January 12, 2026
MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

July 24, 2025
Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

November 26, 2025
Easy methods to Host a Storj Node – Setup, Earnings & Experiences

Easy methods to Host a Storj Node – Setup, Earnings & Experiences

March 11, 2025
Kuwait bans Bitcoin mining over power issues and authorized violations

Kuwait bans Bitcoin mining over power issues and authorized violations

2
The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

2
Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

1
Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

1

Ripple Donates $300K to Flood Relief in Nepal and Tibet Through WCK, Mercy Corps

August 29, 2026

LRN Corporation Wins Gold & Silver in Brandon Hall Group™ HCM Excellence Awards for Sixth Consecutive Year

August 29, 2026

Treasury Proposes Stablecoin Licensing Rules Under GENIUS Act

August 29, 2026

Ledger patched critical signing bugs months after writing the fixes

August 29, 2026

CoinInight

Welcome to CoinInsight.co.uk – your trusted source for all things cryptocurrency! We are passionate about educating and informing our audience on the rapidly evolving world of digital assets, blockchain technology, and the future of finance.

Categories

  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Ethereum
  • Future of Crypto
  • Market
  • Regulation
  • Ripple

Recent News

Ripple Donates $300K to Flood Relief in Nepal and Tibet Through WCK, Mercy Corps

August 29, 2026

LRN Corporation Wins Gold & Silver in Brandon Hall Group™ HCM Excellence Awards for Sixth Consecutive Year

August 29, 2026
  • About
  • Privacy Poilicy
  • Disclaimer
  • Contact

© 2025- https://coininsight.co.uk/ - All Rights Reserved

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining

© 2025- https://coininsight.co.uk/ - All Rights Reserved

Social Media Auto Publish Powered By : XYZScripts.com
Verified by MonsterInsights