CRITICAL LEDGER VULNERABILITY: ETH APP PATCHED
A critical security vulnerability has been discovered in the Ethereum app on Ledger hardware wallets. The issue could allow a malicious application to alter ETH transaction details during the signing process without showing the modification on the Ledger device screen.
This creates a risk at the transaction confirmation stage, one of the key security layers of a hardware wallet. The information displayed on the device could appear correct while the underlying transaction data had already been modified.
Ledger has patched the vulnerability in Ethereum app version 1.22.2.
To reduce risk, devices running an older Ethereum app should be updated to version 1.22.2 or later, along with the latest Ledger Live and Ledger firmware.
Transaction signing should be paused until the full update process is completed. The issue is relevant not only to ETH storage but also to assets operating across the Ethereum ecosystem when managed through Ledger.
The incident is another reminder that hardware wallets are not an absolute security layer when their supporting software is outdated. Checking the app version, firmware and signing environment remains an important part of digital-asset security.
Should hardware-wallet manufacturers add another independent verification layer for transaction data before signing is allowed?
Please do your own research carefully before making any transactions (DYOR). $ETH $XRP $BTR #Colecolen