Security flaw in Ledger's Ethereum app allowed transactions to be swapped
Security researchers at OneKey Anzen have successfully replicated an attack on version 1.22.1 of the Ledger Ethereum app. A vulnerability in the software allowed an attacker to invisibly swap a transaction while the user approved a different transaction on the screen. Ledger has since fixed the problem and advises users to update their app.
In brief:
- OneKey Anzen reproduced an attack in which an approved transaction on a Ledger device was replaced by a different, invisible transaction.
- The cause is a vulnerability in the Ledger Ethereum app version 1.22.1, caused by a timing issue between the display logic and the transaction buffer.
- Ledger has fixed the vulnerability in version 1.22.3 of the Ethereum app and says there is no evidence of actual exploitation.
How the attack works
Yishi, founder of OneKey, explains that the attack revolves around a timing issue in the Ledger Ethereum app. At the moment a user views and approves a transaction on the screen, an attacker can write another transaction to the buffer in the background.
The result: the user sees transaction A, approves transaction A, but the device signs transaction B. That second transaction never appears on the user’s screen.
Yishi says his team was able to fully reproduce the attack, from start to finish, by rebuilding the application itself and bypassing a known test environment error.
Ledger acknowledges vulnerability and issues update
Ledger has officially documented the vulnerability as LSB 023. The company explains that some apps built with the Ledger Secure SDK could still receive new commands during the confirmation screen, causing the displayed transaction data to differ from what was actually signed. According to Ledger, the problem lies in the handling of input and output within the SDK, not in the operating system or firmware of the device itself.
The fix was implemented through changes at the app level and an SDK update. SDK version 26.6.1 was released on 21 August. Users must update their apps via Ledger Live, as a firmware update alone is not sufficient. Ledger says it has no indications that the vulnerability has actually been exploited.
The community notes on the original tweet point out that the vulnerability was already disclosed by TestMachine on 22 August, and that Ledger had already fixed it in version 1.22.2, not in 1.22.3 as Yishi claims. Anyone still running an older version of the Ethereum app would be wise to update it as soon as possible.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.