Ledger Says Ethereum App Flaw Was Patched Before Disclosure
OneKey reproduced a transaction replacement attack affecting an outdated version of Ledger’s Ethereum app, renewing scrutiny of the safeguards underpinning hardware wallets. The weakness could allow transaction details to be substituted during the signing process, a sensitive issue because users rely on a hardware device’s display and isolated environment to verify what they are authorizing before funds are moved.
Ledger rejected claims that it had been hacked, saying the vulnerable Ethereum app had already been patched in an updated release before OneKey disclosed the issue. The company said it had found no evidence that the flaw was exploited in the wild and that no users suffered losses. Ledger urged customers still running an older version of the Ethereum app to upgrade to the latest release as soon as possible.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →