OneKey just publicly reproduced a Ledger exploit, start to finish
- the claim: Ledger's Ethereum app (v1.22.1) could sign a transaction different from the one shown on screen
- you approve transaction A
- the device actually signs transaction B, the one you never saw
- reproduced end to end, no theory
Ledger patched it in 1.22.3, update or stay exposed
can't verify this myself, but a rival naming an exact version number in public is not nothing.
Drop your Ledger firmware version below — let's see how many of you already updated.
already checked mine)
#oneKey #Ledger #exploit
$ETH
- the claim: Ledger's Ethereum app (v1.22.1) could sign a transaction different from the one shown on screen
- you approve transaction A
- the device actually signs transaction B, the one you never saw
- reproduced end to end, no theory
Ledger patched it in 1.22.3, update or stay exposed
can't verify this myself, but a rival naming an exact version number in public is not nothing.
Drop your Ledger firmware version below — let's see how many of you already updated.
already checked mine)
#oneKey #Ledger #exploit
$ETH
