Ledger released Ethereum app version 1.22.3 on Aug. 25 to close two signing vulnerabilities, LSB-024 and LSB-025, that remained in the previous release. The update comes after rival wallet maker OneKey reproduced a separate command-interleaving flaw, LSB-023, against the older 1.22.1 build that Ledger had already patched in version 1.22.2 on Aug. 13. Ledger's security team said no Ledger user was hacked and pointed to a lack of evidence of exploitation in the wild. Chief Technology Officer Charles Guillemet drew a sharp line between a laboratory reproduction on outdated software and a live attack.
Why it matters
LSB-024 and LSB-025 are different in kind from the OneKey-demonstrated bug. LSB-024 allowed a malicious operation array of 257 entries to wrap an 8-bit counter, signing a full batch while the device displayed only the final operation. LSB-025 let a swap provider substitute a token approval for an expected payment because the app never verified the requested action was actually a transfer. Both required a compromised host, neither could move funds on its own, and Ledger confirmed no real-user losses.
The release history is the uncomfortable read. Ledger's own records show the LSB-024 fix was merged on May 5 and the LSB-025 swap-validation fix on May 25, months before 1.22.2 shipped on Aug. 13. The bulletins do not explain the gap, and the company is leaning on updateability as a feature rather than treating the lag as a process failure.
Market impact
For Ledger customers the operational read is concrete: firmware updates do not install the Ethereum app, so users need to push version 1.22.3 through Ledger Live and verify the version on-device. For the broader hardware-wallet category the episode hands competitors a narrative line. OneKey, Trezor and the multisig cohort have all marketed against blind-signing risks, and a vendor of Ledger's scale disclosing two unpatched signing paths on the same day it defends itself against a rival's reproduction is the kind of news cycle that drives cold-storage users toward diversification.
Frequently asked questions
-
What did Ledger's Ethereum app 1.22.3 fix?
It closed two signing flaws, LSB-024 (an array-count overflow that could hide a full batch behind one displayed operation) and LSB-025 (a swap path that could substitute a token approval for an expected payment). Both required a compromised host to exploit.
-
How is this different from the OneKey-demonstrated bug?
OneKey reproduced LSB-023, a command-interleaving flaw in the older 1.22.1 build. Ledger had already patched that in version 1.22.2 on Aug. 13. LSB-024 and LSB-025 are separate vulnerabilities that stayed open until the 1.22.3 release.
-
Was any Ledger user actually hacked?
Ledger's security team said no Ledger user was hacked and that the OneKey demonstration was a laboratory reproduction against outdated software. CTO Charles Guillemet drew the same line. Ledger reports no evidence of exploitation in the wild.
-
Why is the May-to-August gap important?
Ledger's own records show the LSB-024 fix was merged on May 5 and the LSB-025 swap-validation fix on May 25, months before version 1.22.2 shipped on Aug. 13. The bulletins do not explain why those changes did not land in the earlier release.
-
How should Ledger users update?
Push Ethereum app 1.22.3 through Ledger Live and verify the version on the device. A hardware-wallet firmware update does not replace the Ethereum application, so updating the firmware alone is not enough.
CryptoSlate