Ledger Wallet Vulnerability; Users Must Update Ethereum App to Version 1.22.2
A security vulnerability has been identified in the Ethereum application of Ledger hardware wallets that could allow a malicious dApp to sign a transaction different from what is displayed on the device screen under certain conditions. Ledger has released version 1.22.2 of the Ethereum application to address this issue, and users are urged to install it as soon as possible.
According to Mihan Blockchain, this vulnerability was related to the way simultaneous signature requests were managed. In the attack scenario, the details of the original transaction were still displayed on the device screen, but a second request could replace it in memory, ultimately sending different data for signing to the device.
How Did the Vulnerability Work?
According to a report by the security company TestMachine, exploiting this bug required a dApp with WebHID access, a feature that allows certain web applications to communicate directly with hardware devices.
In this scenario, the attacker could send a second signature request while the user was reviewing a transaction. This request would replace the previous transaction data in memory without initiating a new review process. As a result, the user would still see the initial transaction information on the display but would sign the replaced data upon selecting the confirm option.
TestMachine also stated that it reproduced this scenario on the Ledger Flex.
What Changes Did Ledger Make to Fix the Issue?
The recorded changes in Ledger's official code indicate that the company added two security controls to prevent the attack. First, the application no longer allows a new signature request to interrupt the review process of an ongoing transaction. Second, when receiving a confirmation command, the current status of the signing process is checked, and if it does not match the expected status, the request will be rejected.
These fixes have been implemented in version 1.22.2 of the Ethereum application, which was released on August 12. However, TestMachine claims that this version has not yet been fully made available to users.
According to TestMachine, due to the use of shared code, this flaw could also affect the Nano X, Nano S Plus, Stax, and Apex models. The official file for version 1.22.2 also lists these models alongside Ledger Flex as target devices for the Ethereum application.
Ledger has not yet specified which was the first vulnerable version of this application. Therefore, it is unclear how many previous versions contained this bug.
Discrepancy Between Ledger and TestMachine on Discovering the Vulnerability
Charles Guillemet, Chief Technology Officer of Ledger, announced on August 23 that Ledger's internal security team, Ledger Donjon, had identified this bug before TestMachine contacted the company through its bug bounty program.
Guillemet stated that this team had identified and fixed the issue in some "transparent signing" processes about two weeks before his statement. In contrast, TestMachine claimed that the Azimuth system identified this vulnerability and shared its findings with Ledger, confirming their validity.
Despite this discrepancy in narratives regarding the timing and manner of discovering the vulnerability, both parties have confirmed the existence of the problem and its fix in the application code.
It is worth noting that, so far, there have been no confirmed cases of exploitation of this vulnerability in the real world, theft of user assets, or extraction of private keys reported. However, since the flaw directly relates to the transaction verification and signing process, updating the application is of particular importance.
Ledger users should check the version of the Ethereum application on their device and upgrade it to 1.22.2 if they are using an older version. Ledger has also advised users to keep not only the Ethereum application but also the device's operating system, other applications, and related client software updated to the latest version.
Additionally, this vulnerability differs from another security flaw previously reported in Ledger's native Zilliqa application and is unrelated to the 2023 attack on Connect Kit.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

The Sandbox Launches SAND Compensation Claim for Attack, Deadline September 22

$2.3 Billion "Out of Thin Air": How Trump's Crypto Empire Is Bankrupting Investors and Selling Influence to UAE Sheikhs

NVDA Stock Price Prediction: What Jensen Huang's "AGI Has Arrived" Claim Actually Means

Turkey to Sign Agreement with Russia to Increase Fertilizer Imports

MoonPay CEO Asks Claude to Book a Flight Before Stuffing a Crypto Wallet into the Chatbox

Hunter Biden Crypto Coin Explained: What Is $LAPTOP and Why Did He Launch It?
Hunter Biden's crypto coin $LAPTOP explained: launch date, tokenomics, the $TRUMP comparison, and the scam risks to know before you trade.

WEEX Stock Spot 2.0 Guide: Pick the Top 3 Stocks for 2× Rewards + 100K USDT Pool

WEEX P2P now supports VES—Merchant Recruitment Now Open

WEEX P2P now supports NPR—Merchant Recruitment Now Open

WEEX P2P now supports GBP—Merchant Recruitment Now Open

L2 Profits Soar, What About Ethereum?

Tether Alloy Gold-Backed Reserves Cross $210M

Harmony Cites AI Threats in Proposed Blockchain Shutdown

Bitget Wallet Launches Assetback Rewards In Bitcoin And Tokenized Assets

How to mine Bitcoin: A beginner’s guide to mining BTC-Top 4 cloud mining sites in 2026

Baidu Stock Connect Access: Can Shares Rise by 20% in a Month?

How to Use the WEEX Telegram Mini App: No Download Needed, Plus Rewards and an iPhone 17 Pro Chance

Bitcoin Emerges as a 'Safe Haven' in the Middle East Amid Iran Conflict, Says BPI Analysis
![[ETH Letter] Proposal for Activation of Sepolia Glamsterdam Testnet on October 6](/public-static/34_874859b143.png?format=avif)
[ETH Letter] Proposal for Activation of Sepolia Glamsterdam Testnet on October 6

What is Stronghold (SHX)? An Overview of Stellar's Payment Token

Von der Leyen Arrives in Greenland to Sign Declaration Amid Trump's Claims

Harmony Plans to Shut Down Mainnet and Migrate ONE to Ethereum, Shifting Focus to AI Video Remix Business

Crypto: Essential Tips for Developers to Protect Their Computers and Wallets

Market Value of Altcoins Surpasses $200 Billion

The calendar began to press

Cathie Wood Points to Strong August Jobs as a Sign of Technology-Driven Deflation

Bitcoin Gains a Strategic Place in the Economy of the United Arab Emirates

Trading Tokenized Gold: XAUT Soars to $4,430, Whales Buy Without Selling

WEEX TradFi Lucky Egg Event: Trade Futures Daily and Win Up to 10,000 USDT Position Airdrops

Cryptocurrency Fills the 900 Million Annual Fee Pit for Robots
The Sandbox Launches SAND Compensation Claim for Attack, Deadline September 22
$2.3 Billion "Out of Thin Air": How Trump's Crypto Empire Is Bankrupting Investors and Selling Influence to UAE Sheikhs
NVDA Stock Price Prediction: What Jensen Huang's "AGI Has Arrived" Claim Actually Means
Turkey to Sign Agreement with Russia to Increase Fertilizer Imports
MoonPay CEO Asks Claude to Book a Flight Before Stuffing a Crypto Wallet into the Chatbox
Hunter Biden Crypto Coin Explained: What Is $LAPTOP and Why Did He Launch It?
Hunter Biden's crypto coin $LAPTOP explained: launch date, tokenomics, the $TRUMP comparison, and the scam risks to know before you trade.








