😬 A vulnerability was found at Ledger in the principle of “what you see is what you sign”

Researchers discovered a problem in the Ethereum app for Ledger: when reviewing a transaction, the device could receive a new command before finishing the previous one. As a result, the data the user saw on the screen could differ from the parameters of the actual signature.

The irony is obvious: Clear Signing was created specifically so that the Ledger screen is the source of truth — “what you see is what you sign”.

The vulnerability affected Ethereum app versions up to 1.22.3. Ledger has released a fix and recommends updating the app. Important: the company does not report that this issue has been exploited against users.

So this is not a story about “Ledger being hacked.” It’s a much more interesting lesson: even a hardware wallet can’t just show you a screen and say “trust me.” Security has to be ensured across the entire chain, from receiving data to the moment of signing.

I’ve always said that the “Secure” label on the box isn’t a magic spell. In crypto, security ends where you stop checking what exactly you are signing. Now Ledger has another reason to remind its users about this — follow @MoonMan567 if you want to see such stories without marketing gloss.