Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Biodiversity corridor payments boost household incomes in Vietnam’s Annamite mountains

    September 14, 2026

    Iranian cargo vessel struck near Qeshm Island as Oman delays Tehran-Gulf talks

    September 14, 2026

    What’s behind the AI industry’s latest warnings of doom?

    September 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Biodiversity corridor payments boost household incomes in Vietnam’s Annamite mountains
    • Iranian cargo vessel struck near Qeshm Island as Oman delays Tehran-Gulf talks
    • What’s behind the AI industry’s latest warnings of doom?
    • Anthropic’s 3-Step ‘Pace the Frontier’ Plan Wins OpenAI, xAI and Microsoft Support: Is It Too Late to Slow AI Down?
    • US hosts G20 energy talks in Texas as Iran war disrupts global fuel markets
    • The perilous economic conditions facing the UK can be traced back to Trump | Richard Partington
    • Andy Burnham to host entrepreneurs and local mayors at No 10 on Monday | Economic policy
    • Crypto’s biggest week ever? Swarm fears prompt AI slowdown: Hodler’s Digest
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    Ledger patched critical signing bugs months after writing the fixes

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 28, 2026 Crypto & Blockchain No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Crypto wallet maker Ledger is urging its Ethereum app users to update again after two signing flaws remained in its previous security release.

    The hardware-wallet maker published Ethereum app version 1.22.3 on Aug. 25, closing vulnerabilities that could hide operations from a device review or authorize a token approval in place of an expected payment.

    The update follows controversy over a separate Ethereum signing flaw reproduced by rival wallet maker OneKey. That issue, tracked as LSB-023, affected older versions and allowed a compromised host to interleave commands so that transaction parameters could change after being displayed but before signing.

    Ledger said OneKey demonstrated the bug against version 1.22.1 after the company had already fixed it in Ethereum app 1.22.2, released Aug. 13.

    Related Reading

    Ledger patched an Ethereum app bug that could show one transaction and sign another

    “No Ledger user was hacked,” Ledger’s security team said, describing the demonstration as a laboratory reproduction involving outdated software. The company said it had found no evidence of exploitation in the wild.

    Ledger Chief Technology Officer Charles Guillemet made the same distinction, saying reproducing an already-patched flaw did not amount to “hacking Ledger.”

    Version 1.22.2, however, did not close every known Ethereum-app vulnerability on Ledger. Instead, two separate flaws, LSB-024 and LSB-025, remained until the release of 1.22.3.

    Two additional signing paths remained exposed

    LSB-024 affected how the Ethereum app processed arrays of operations during clear signing.

    The app read the number of operations using a 16-bit value but stored the remaining count in an 8-bit field. In Ledger’s proof of concept, an array containing 257 operations wrapped the counter back to one, causing the device to display only the final operation even though its signature authorized the entire batch.

    Exploitation required a compromised host and an unusually large attacker-controlled operation array. Ledger tested the scenario on a private network fork and reported no real-user losses.

    The Daily Brief

    The signal, before the noise.

    Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.

    One email. Everything that matters.

    Free to join. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re on the list. Your next Daily Brief is on its way.

    The second vulnerability, LSB-025, affected the token-payment path used by Ledger’s Exchange application during swaps.

    Comparison of Ledger Ethereum app flaws LSB-024 and LSB-025, their affected versions, narrow trigger conditions, and the update to version 1.22.3

    Ledger’s app checked the token, quantity, and destination but did not verify that the requested action was actually a payment. A malicious or compromised swap provider could therefore substitute a token approval matching those same parameters and have it signed without an additional device prompt.

    The flaw could not create an unlimited approval, switch to another token, or grant permission to an arbitrary address. An approval also does not itself transfer funds, requiring a subsequent transaction before the approved assets could move.

    Ledger said it found no evidence that the swap vulnerability was exploited.

    The release history raises a separate question. Ledger’s records show the fix for the array-count issue was merged on May 5 and the swap-validation correction on May 25, months before version 1.22.2 was released. Its security bulletins do not explain why those changes were absent from that update.

    Ledger defended its broader approach by pointing to updateability as central to hardware wallet security. Its security team said it continuously identifies vulnerabilities through internal research and external bug-bounty programs, then patches them through software releases.

    For users, the distinction between the three vulnerabilities is important. Version 1.22.2 fixed the command-interleaving flaw later reproduced by OneKey, while version 1.22.3 is required to address the two additional signing bugs disclosed Aug. 27.

    Ledger recommends installing Ethereum app 1.22.3 or later through Ledger Live and verifying the version on the device. Updating the hardware wallet firmware alone does not replace the affected Ethereum application.

    Bugs critical Fixes Ledger months Patched signing writing
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Crypto’s biggest week ever? Swarm fears prompt AI slowdown: Hodler’s Digest

    DeFi audit scope study: what the 94% loss figure means

    Symbiosis bridge exploit: 15 BTC recovered, LP terms pending

    Albuquerque Bans Bitcoin ATMs, Giving Operators 45 Days to Remove Them

    EU Regulator Says Prediction Markets Are ‘Rife With Inside Trading’

    Blockstream Refuses Ransom for Return of $47M in Bitcoin from Liquid Hack: ‘It Is Theft’

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Biodiversity corridor payments boost household incomes in Vietnam’s Annamite mountains

    September 14, 2026

    Iranian cargo vessel struck near Qeshm Island as Oman delays Tehran-Gulf talks

    September 14, 2026

    What’s behind the AI industry’s latest warnings of doom?

    September 14, 2026

    Anthropic’s 3-Step ‘Pace the Frontier’ Plan Wins OpenAI, xAI and Microsoft Support: Is It Too Late to Slow AI Down?

    September 14, 2026
    Latest Posts

    Bridge collapse in DR Congo reignites debate about mining revenues

    August 3, 2026

    How many people die trying to cross the Channel in a small boat? – Full Fact

    August 3, 2026

    The Guardian view on events in Ceuta: chaos and tragedy are weaponised by the far right | Editorial

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Biodiversity corridor payments boost household incomes in Vietnam’s Annamite mountains

    September 14, 2026

    Iranian cargo vessel struck near Qeshm Island as Oman delays Tehran-Gulf talks

    September 14, 2026

    What’s behind the AI industry’s latest warnings of doom?

    September 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.