Ledger Patches Ethereum App Signing Flaw, Says Users on Latest Version Are Protected
Forecast Trend Report by Period



Ledger has patched a security flaw affecting part of the signing process in its Ethereum app.
Wu Blockchain reported on August 24 that Ledger Chief Technology Officer Charles Guillemet said the company's security research team, Ledger Donjon, found the vulnerability in part of the app's clear-signing process and completed a fix about two weeks ago.
Clear signing lets users review transaction details, including the recipient and amount, in a human-readable format before signing a blockchain transaction. The flaw was found in some signing flows that use that feature.
Users who keep their Ledger device firmware and related applications updated to the latest versions are protected from the vulnerability, Guillemet said.
He also criticized the way an external security firm disclosed the flaw. Guillemet said a company that identified itself as a smart-contract security firm disclosed the vulnerability after Ledger had completed the patch rollout and then suggested the issue had not been resolved.
Suehyeon Lee
shlee@bloomingbit.ioI'm reporter Suehyeon Lee, your Web3 Moderator.