Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Songs created by AI banned from Australia’s music charts

    August 25, 2026

    UK drone factories may face attacks from ‘unknown sources’ says Kremlin advisor

    August 25, 2026

    SEC subpoenas Wall Street banks over Situational Awareness

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Songs created by AI banned from Australia’s music charts
    • UK drone factories may face attacks from ‘unknown sources’ says Kremlin advisor
    • SEC subpoenas Wall Street banks over Situational Awareness
    • India’s Airbound bags $37M to take on trucks with rocket-like drones
    • 91 Vulnerabilities Patched in Spring Application Framework
    • Ledger patched an Ethereum app bug that could show one transaction and sign another
    • Scientists just imaged the hidden quantum shape of a molecule
    • Wind energy surplus fuels unregulated data centers in Brazil’s dry land
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    Ledger patched an Ethereum app bug that could show one transaction and sign another

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 25, 2026 Crypto & Blockchain No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ledger users should update the Ethereum app to version 1.22.2 after official code changes showed that a malicious dApp or other connected host could start a second signing command while a transaction was still under review.

    In the path described by security company TestMachine, pressing approve could return a signature for substituted data instead of the transaction shown on the device.

    TestMachine said on Aug. 22 that the attack required a dApp with WebHID access. The group said a second command could replace the transaction held in memory without opening a new review, leaving the original details on screen while the device signed the replacement.

    It said the behavior was validated on Ledger Flex.

    Ledger’s code history shows one official fix commit saying new signing commands could tear down an active review before returning an error. Another added state checks because approval callbacks previously signed without confirming that the app remained in the expected signing state.

    Version 1.22.2 closes that documented path by refusing a new signing session during an active review and rejecting an approval callback when the state no longer matches. The reviewed sources establish a code-level fix for those entry and callback defects.

    Flowchart of the researcher-described Ledger Ethereum signing race and the two safeguards added in app version 1.22.2
    Diagram showing the signing-state race described for Ledger’s Ethereum app and the safeguards added in version 1.22.2.

    TestMachine asserted that shared code extended the issue to Nano X, Nano S Plus, Stax, and Apex, and the tagged app manifest lists those models alongside Flex as build targets.

    The Daily Brief

    The signal, before the noise.

    Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.

    One email. Everything that matters.

    Free to join. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re on the list. Your next Daily Brief is on its way.

    Ledger’s release comparison starts from version 1.22.1, while the earliest affected app release remains undisclosed.

    Related Reading

    A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds

    Ledger’s changelog dates 1.22.2 to Aug. 12, GitHub shows the signed tag on Aug. 13, and TestMachine said on Aug. 22 that the fix was not yet released.

    Ledger CTO Charles Guillemet said on Aug. 23 that Ledger Donjon had found a bug in “certain clear signing flows” and deployed the fix about two weeks earlier. The sources leave open whether TestMachine was referring to distribution through Ledger Wallet.

    Guillemet said Donjon found the bug before TestMachine contacted Ledger’s bounty program, while TestMachine said its Azimuth system found the issue and that it shared and verified the finding with Ledger.

    Users should confirm that Ethereum app 1.22.2 is installed. Guillemet also advised keeping device firmware, apps, and client software current, although the public sources give no firmware minimum specific to this flaw.

    They report no confirmed in-the-wild exploitation, lost funds, or private-key extraction.

    The issue is separate from the native Zilliqa Ledger app flaw involving Schnorr nonce leakage and the 2023 Connect Kit compromise, which involved a malicious JavaScript library and reported losses.

    app Bug Ethereum Ledger Patched show sign transaction
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    91 Vulnerabilities Patched in Spring Application Framework

    BNB Chain Activates Pasteur Hard Fork on BSC

    Strive Buys $81.5 Million in Bitcoin After Issuing More Shares

    I tried Meta’s new free vibe coding app to make my own games, and it was surprisingly fun

    Korean Bank Taps Ripple For Payments, Pakistan Opens Crypto Licensing: Asia Express

    Coinbase launches B20 tokenized stocks on Base

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Songs created by AI banned from Australia’s music charts

    August 25, 2026

    UK drone factories may face attacks from ‘unknown sources’ says Kremlin advisor

    August 25, 2026

    SEC subpoenas Wall Street banks over Situational Awareness

    August 25, 2026

    India’s Airbound bags $37M to take on trucks with rocket-like drones

    August 25, 2026
    Latest Posts

    The Doctor and His Diary: What Fauci’s Innermost Musings Reveal

    July 29, 2026

    Iran Considered Retaliatory Strike on Ukrainian Seaport

    July 29, 2026

    The French presidential candidate who wants to blow up the Franco-German engine – POLITICO

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Songs created by AI banned from Australia’s music charts

    August 25, 2026

    UK drone factories may face attacks from ‘unknown sources’ says Kremlin advisor

    August 25, 2026

    SEC subpoenas Wall Street banks over Situational Awareness

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.