Login
Sign Up
Woofun AI reports that a critical vulnerability allowing silent transaction substitution was patched in the Ledger Ethereum app, necessitating immediate user updates. The flaw enabled malicious dApps or connected hosts to initiate secondary signing commands while primary transactions were under active review.
According to security firm TestMachine, the exploit mechanism allowed users to approve on-screen transactions while the device actually signed substituted data. Version 1.22.2 specifically targets this vector by blocking concurrent signing attempts.
Woofun AI data shows the update mandates strict session isolation to prevent such interference.
The patch resolves entry and callback defects by refusing new signing sessions during active reviews. It also rejects approval callbacks if the internal state mismatch is detected. These code-level changes ensure the signed data matches the displayed transaction.
No confirmed in-the-wild exploitation has occurred, with no lost funds or private-key extraction reported. This incident highlights the persistent risks of interface manipulation in hardware wallet ecosystems.