|

Ledger says the viral “hack” was already patched, but two real bugs still needed fixing

Comparison of Ledger Ethereum app flaws LSB-024 and LSB-025, their affected versions, narrow trigger conditions, and the update to version 1.22.3

Crypto pockets maker Ledger is urging its Ethereum app customers to replace once more after two signing flaws remained in its earlier safety launch.

The hardware-wallet maker revealed Ethereum app model 1.22.3 on Aug. 25, closing vulnerabilities that might conceal operations from a tool overview or authorize a token approval rather than an anticipated fee.

The replace follows controversy over a separate Ethereum signing flaw reproduced by rival pockets maker OneKey. That concern, tracked as LSB-023, affected older variations and allowed a compromised host to interleave instructions in order that transaction parameters might change after being displayed but earlier than signing.

Ledger mentioned OneKey demonstrated the bug in opposition to model 1.22.1 after the firm had already fastened it in Ethereum app 1.22.2, launched Aug. 13.

Related Reading

Ledger patched an Ethereum app bug that could show one transaction and sign another


“No Ledger consumer was hacked,” Ledger’s safety staff said, describing the demonstration as a laboratory copy involving outdated software program. The firm mentioned it had discovered no proof of exploitation in the wild.

Ledger Chief Technology Officer Charles Guillemet made the similar distinction, saying reproducing an already-patched flaw didn’t quantity to “hacking Ledger.”

Version 1.22.2, nevertheless, didn’t shut each identified Ethereum-app vulnerability on Ledger. Instead, two separate flaws, LSB-024 and LSB-025, remained till the launch of 1.22.3.

Two further signing paths remained uncovered

LSB-024 affected how the Ethereum app processed arrays of operations throughout clear signing.

The app learn the variety of operations utilizing a 16-bit worth but saved the remaining rely in an 8-bit discipline. In Ledger’s proof of idea, an array containing 257 operations wrapped the counter again to 1, inflicting the gadget to show solely the ultimate operation despite the fact that its signature approved the total batch.

Exploitation required a compromised host and an unusually giant attacker-controlled operation array. Ledger examined the state of affairs on a personal community fork and reported no real-user losses.

The second vulnerability, LSB-025, affected the token-payment path utilized by Ledger’s Exchange utility throughout swaps.

Comparison of Ledger Ethereum app flaws LSB-024 and LSB-025, their affected versions, narrow trigger conditions, and the update to version 1.22.3

Ledger’s app checked the token, amount, and vacation spot but didn’t confirm that the requested motion was really a fee. A malicious or compromised swap supplier might due to this fact substitute a token approval matching those self same parameters and have it signed with out an extra gadget immediate.

The flaw couldn’t create an infinite approval, change to a different token, or grant permission to an arbitrary handle. An approval additionally doesn’t itself switch funds, requiring a subsequent transaction earlier than the authorized property might transfer.

Ledger mentioned it discovered no proof that the swap vulnerability was exploited.

The launch historical past raises a separate query. Ledger’s data present the repair for the array-count concern was merged on May 5 and the swap-validation correction on May 25, months earlier than model 1.22.2 was launched. Its safety bulletins don’t clarify why these modifications have been absent from that replace.

Ledger defended its broader strategy by pointing to updateability as central to hardware wallet safety. Its safety staff mentioned it constantly identifies vulnerabilities by means of inside analysis and exterior bug-bounty applications, then patches them by means of software program releases.

For customers, the distinction between the three vulnerabilities is necessary. Version 1.22.2 fastened the command-interleaving flaw later reproduced by OneKey, whereas model 1.22.3 is required to handle the two further signing bugs disclosed Aug. 27.

Ledger recommends putting in Ethereum app 1.22.3 or later by means of Ledger Live and verifying the model on the gadget. Updating the hardware wallet firmware alone doesn’t change the affected Ethereum utility.

The submit Ledger says the viral “hack” was already patched, but two real bugs still needed fixing appeared first on CryptoSlate.

Similar Posts