Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
- Ledger’s Ethereum app 1.22.2 blocks signing-session replacement and mismatched approval callbacks that could sign substituted transaction data.
- The flaw could leave transaction details unchanged on-screen while a connected malicious dApp obtained a signature for different data.
- Public validation covered Ledger Flex, while broader model impact, disclosure timing, and the earliest affected release remain unresolved.
Ledger users should update the Ethereum app to version 1.22.2 after official code changes showed that a malicious dApp or other connected host could start a second signing command while a transaction was still under review.
In the path described by security company TestMachine, pressing approve could return a signature for substituted data instead of the transaction shown on the device.
TestMachine said on Aug. 22 that the attack required a dApp with WebHID access. The group said a second command could replace the transaction held in memory without opening a new review, leaving the original details on screen while the device signed the replacement.
It said the behavior was validated on Ledger Flex.
Ledger’s code history shows one official fix commit saying new signing commands could tear down an active review before returning an error. Another added state checks because approval callbacks previously signed without confirming that the app remained in the expected signing state.
Version 1.22.2 closes that documented path by refusing a new signing session during an active review and rejecting an approval callback when the state no longer matches. The reviewedfects

TestMachine asserted that shared code extended the issue to Nano X, Nano S Plus, Stax, and Apex, and the tagged app manifest lists those models alongside Flex as build targets.
Ledger’s release comparison starts from version 1.22.1, while the earliest affected app release remains undisclosed.
A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
Ledger’s changelog dates 1.22.2 to Aug. 12, GitHub shows the signed tag on Aug. 13, and TestMachine said on Aug. 22 that the fix was not yet released.
Ledger CTO Charles Guillemet said on Aug. 23 that Ledger Donjon had found a bug in “certain clear signing flows” and deployed the fix about two weeks earlier. Theon through Ledger Wallet
Guillemet said Donjon found the bug before TestMachine contacted Ledger’s bounty program, while TestMachine said its Azimuth system found the issue and that it shared and verified the finding with Ledger.
Users should confirm that Ethereum app 1.22.2 is installed. Guillemet also advised keeping device firmware, apps, and client software current, although the public
They report no confirmed in-the-wild exploitation, lost funds, or private-key extraction.
The issue is separate from the native Zilliqa Ledger app flaw involving Schnorr nonce leakage and the 2023 Connect Kit compromise, which involved a malicious JavaScript library and reported losses.
Related AssetEthereum#2ETH$2,495.5324-hour change: up2.30%Loading price history…24HUp2.30%7DUp31.60%30DUp32.89%Related CompanyLedgerCrypto hardware walletsRelated PersonCharles GuillemetCTO · Ledger
FeaturedEthereumTechnologyHacksWallets
Editorial credits
Source: cryptoslate.com

2 Comments
Pingback: $5,000 Ethereum? Analyst Identifies the Levels That Could Decide ETH’s Next Move – xpertsstudio
Pingback: Bitmine Buys 32,447 ETH, Eyes 5% of Ethereum’s Total Supply – xpertsstudio