Cryptocurrency Prices by Coinlib

No, Ledger Wasn’t Hacked: Weak Ethereum App Was Patched Earlier than Exploit, Firm Says – Decrypt

In short
OneKey reproduced a transaction-replacement assault in opposition to model 1.22.1 of Ledger’s Ethereum app.
Ledger says it fastened the vulnerability in model 1.22.2 earlier than OneKey revealed its take a look at and has seen no proof of assaults in opposition to customers.
Ledger recommends putting in Ethereum app model 1.22.3 or later and checking the app model on the system.
Cryptocurrency pockets developer Ledger rejects claims that it had been hacked after researchers at rival pockets maker OneKey reproduced a transaction-replacement vulnerability utilizing an outdated model of Ledger’s Ethereum app.On Thursday, Yishi Wang, founder and CEO of OneKey, mentioned on X that the corporate’s Anzen safety workforce recreated the assault in opposition to Ethereum app model 1.22.1 in a lab.Myriad: Ethereum subsequent value transfer? Click on to make your prediction.“The bug is a race situation between the transaction show logic and the underlying transaction buffer,” Wang wrote. “An attacker can overwrite the transaction ready to be signed whereas the person remains to be reviewing a authentic one.”That may imply a hacker who had compromised the software program speaking with a susceptible Ledger app may present the person a authentic Ethereum transaction, then change its particulars earlier than signing, redirecting funds to the hacker’s pockets with out the change showing on the system.Ledger Chief Expertise Officer Charles Guillemet rejected OneKey’s characterization, saying that reproducing an already-patched bug doesn't quantity to “hacking Ledger.”“What this thread describes is a vulnerability in an outdated model of the Ethereum app,” he responded on X. “It was recognized by way of our safety course of and glued in Ethereum app 1.22.2, launched August 13, earlier than this submit.”In a safety bulletin revealed on Thursday, Ledger mentioned the flaw may trigger an affected app to show one transaction whereas signing one other. An attacker would first want to regulate communications between the system and its host by way of malware, a compromised pockets app or a hostile web site.Ledger mentioned it discovered no proof that anybody exploited the vulnerability outdoors a laboratory.“No person was hacked. No exploitation within the wild,” Guillemet wrote. “Operating an exploit in opposition to an outdated model after the repair has shipped is a lab train, not a discovering.”Ledger added safeguards in Ethereum app model 1.22.2 on Aug. 13, then addressed the underlying situation in Safe SDK model 26.6.1 on Aug. 21 and rebuilt its apps with the corrected software program. The corporate recommends model 1.22.3 or later, which additionally fixes a separate transaction-display vulnerability. Ledger revealed its bulletin on Aug. 27.When requested about Onekey’s claims, Ledger pointed Decrypt to Ledger Donjon, the corporate’s inside safety analysis workforce, which mentioned in a separate X submit that the episode confirmed why {hardware} wallets must help software program updates.“All software program has bugs. {Hardware} wallets are not any exception,” the workforce wrote. “That’s why updateability is a core a part of Ledger’s safety structure: when a vulnerability is discovered, whether or not by our personal Donjon workforce or by exterior researchers, we will patch each system within the discipline. A pockets that may’t be up to date can’t be fastened.”Myriad: Solana's subsequent value transfer? Click on to make your prediction.Ledger suggested clients to put in the most recent firmware and apps by way of Ledger Pockets, replace the Ethereum app to model 1.22.3 or later, and confirm the model proven on the system. Apps and firmware replace individually.Earlier this month, after attackers stole greater than $130 million in Bitcoin from customers of Coldcard air-gapped wallets, Guillemet informed Decrypt that the incident was a warning for the {hardware} pockets trade.“We additionally do not simply depend on our personal phrase for it,” he mentioned. “Our Donjon analysis lab exists to attempt to break our merchandise earlier than anybody else can.”Every day Debrief NewsletterStart on daily basis with the highest information tales proper now, plus unique options, a podcast, movies and extra.