This attack was replicated in a lab environment against the Ethereum app for Ledger version 1.22.1.
• The vulnerability allowed an attacker to modify a pending transaction just before signing.
• Ledger has fixed the vulnerability at the application and SDK level. Users must update their apps through Ledger Live; a firmware update is not sufficient.
• Ledger stated that it has not detected any instances of exploitation of the vulnerability.
Subscribe
Exchanges💰: LBank | Blofin | Bitunix | OKX
Get bonuses — sign up on the exchange!