Loading prices…
🩸BEARISH

Ledger Ethereum App 1.22.3 Patches Two Critical Signing Bugs

Ledger merged the fix for one bug on May 5 and the other on May 25. They shipped in August. The gap between merge and release is the uncomfortable read for hardware-wallet customers.

Ledger released Ethereum app version 1.22.3 on Aug. 25 to close two signing vulnerabilities, LSB-024 and LSB-025, that remained in the previous release. The update comes after rival wallet maker OneKey reproduced a separate command-interleaving flaw, LSB-023, against the older 1.22.1 build that Ledger had already patched in version 1.22.2 on Aug. 13. Ledger's security team said no Ledger user was hacked and pointed to a lack of evidence of exploitation in the wild. Chief Technology Officer Charles Guillemet drew a sharp line between a laboratory reproduction on outdated software and a live attack.

Why it matters

LSB-024 and LSB-025 are different in kind from the OneKey-demonstrated bug. LSB-024 allowed a malicious operation array of 257 entries to wrap an 8-bit counter, signing a full batch while the device displayed only the final operation. LSB-025 let a swap provider substitute a token approval for an expected payment because the app never verified the requested action was actually a transfer. Both required a compromised host, neither could move funds on its own, and Ledger confirmed no real-user losses.

The release history is the uncomfortable read. Ledger's own records show the LSB-024 fix was merged on May 5 and the LSB-025 swap-validation fix on May 25, months before 1.22.2 shipped on Aug. 13. The bulletins do not explain the gap, and the company is leaning on updateability as a feature rather than treating the lag as a process failure.

Market impact

For Ledger customers the operational read is concrete: firmware updates do not install the Ethereum app, so users need to push version 1.22.3 through Ledger Live and verify the version on-device. For the broader hardware-wallet category the episode hands competitors a narrative line. OneKey, Trezor and the multisig cohort have all marketed against blind-signing risks, and a vendor of Ledger's scale disclosing two unpatched signing paths on the same day it defends itself against a rival's reproduction is the kind of news cycle that drives cold-storage users toward diversification.

Related tokens
$ETH

Frequently asked questions

  1. What did Ledger's Ethereum app 1.22.3 fix?

    It closed two signing flaws, LSB-024 (an array-count overflow that could hide a full batch behind one displayed operation) and LSB-025 (a swap path that could substitute a token approval for an expected payment). Both required a compromised host to exploit.

  2. How is this different from the OneKey-demonstrated bug?

    OneKey reproduced LSB-023, a command-interleaving flaw in the older 1.22.1 build. Ledger had already patched that in version 1.22.2 on Aug. 13. LSB-024 and LSB-025 are separate vulnerabilities that stayed open until the 1.22.3 release.

  3. Was any Ledger user actually hacked?

    Ledger's security team said no Ledger user was hacked and that the OneKey demonstration was a laboratory reproduction against outdated software. CTO Charles Guillemet drew the same line. Ledger reports no evidence of exploitation in the wild.

  4. Why is the May-to-August gap important?

    Ledger's own records show the LSB-024 fix was merged on May 5 and the LSB-025 swap-validation fix on May 25, months before version 1.22.2 shipped on Aug. 13. The bulletins do not explain why those changes did not land in the earlier release.

  5. How should Ledger users update?

    Push Ethereum app 1.22.3 through Ledger Live and verify the version on the device. A hardware-wallet firmware update does not replace the Ethereum application, so updating the firmware alone is not enough.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 2h ago
Open original →