{"id":12508,"date":"2026-08-28T12:29:12","date_gmt":"2026-08-28T12:29:12","guid":{"rendered":"https:\/\/cryptonews.uk.com\/?p=12508"},"modified":"2026-08-28T12:29:12","modified_gmt":"2026-08-28T12:29:12","slug":"ledger-patched-critical-signing-bugs-months-after-writing-the-fixes","status":"publish","type":"post","link":"https:\/\/cryptonews.uk.com\/?p=12508","title":{"rendered":"Ledger patched critical signing bugs months after writing the fixes"},"content":{"rendered":"<p><\/p>\n<div data-single-article-content=\"\">\n<p>Crypto wallet maker Ledger is urging its Ethereum app users to update again after two signing flaws remained in its previous security release.<\/p>\n<p>The hardware-wallet maker published Ethereum app version 1.22.3 on Aug. 25, closing vulnerabilities that could hide operations from a device review or authorize a token approval in place of an expected payment.<\/p>\n<p>The update follows controversy over a separate Ethereum signing flaw reproduced by rival wallet maker OneKey. That issue, tracked as LSB-023, affected older versions and allowed a compromised host to interleave commands so that transaction parameters could change after being displayed but before signing.<\/p>\n<p>Ledger said OneKey demonstrated the bug against version 1.22.1 after the company had already fixed it in Ethereum app 1.22.2, released Aug. 13.<\/p>\n<div class=\"cs-article-embed\">\n<p> <span class=\"cs-article-embed__related-reading\">Related Reading<\/span><\/p>\n<h3 class=\"cs-article-embed__title\">Ledger patched an Ethereum app bug that could show one transaction and sign another<\/h3>\n<\/p>\n<p> <span class=\"cs-article-embed__arrow\" aria-hidden=\"true\"> <i class=\"fa-light fa-arrow-up-right\"\/> <\/span> <\/div>\n<p>\u201cNo Ledger user was hacked,\u201d Ledger\u2019s security team said, describing the demonstration as a laboratory reproduction involving outdated software. The company said it had found no evidence of exploitation in the wild.<\/p>\n<p>Ledger Chief Technology Officer Charles Guillemet made the same distinction, saying reproducing an already-patched flaw did not amount to \u201chacking Ledger.\u201d<\/p>\n<p>Version 1.22.2, however, did not close every known Ethereum-app vulnerability on Ledger. Instead, two separate flaws, LSB-024 and LSB-025, remained until the release of 1.22.3.<\/p>\n<h2>Two additional signing paths remained exposed<\/h2>\n<p>LSB-024 affected how the Ethereum app processed arrays of operations during clear signing.<\/p>\n<p>The app read the number of operations using a 16-bit value but stored the remaining count in an 8-bit field. In Ledger\u2019s proof of concept, an array containing 257 operations wrapped the counter back to one, causing the device to display only the final operation even though its signature authorized the entire batch.<\/p>\n<p>Exploitation required a compromised host and an unusually large attacker-controlled operation array. Ledger tested the scenario on a private network fork and reported no real-user losses.<\/p>\n<aside id=\"cs-inline-newsletter-1\" class=\"cs-inline-newsletter\" data-inline-newsletter=\"\" data-newsletter-placement=\"article-midpoint\" data-newsletter-pending-label=\"Joining\u2026\" data-newsletter-pending-status=\"Joining the Daily Brief\u2026\" data-newsletter-email-required-message=\"Before sending, please provide your email address.\" aria-labelledby=\"cs-inline-newsletter-1-title\" aria-describedby=\"cs-inline-newsletter-1-copy\">\n<div class=\"cs-inline-newsletter__inner\">\n<div class=\"cs-inline-newsletter__content\"> <span class=\"cs-inline-newsletter__eyebrow\"> <i class=\"fa-regular fa-envelope\" aria-hidden=\"true\"\/> The Daily Brief <\/span><\/p>\n<h2 id=\"cs-inline-newsletter-1-title\" class=\"cs-inline-newsletter__title\">The signal, before the noise.<\/h2>\n<p id=\"cs-inline-newsletter-1-copy\" class=\"cs-inline-newsletter__copy\">Start your day with the crypto stories moving markets, decoded by CryptoSlate\u2019s editors.<\/p>\n<\/div>\n<div class=\"cs-inline-newsletter__form-shell\">\n<p class=\"cs-inline-newsletter__form-heading\">One email. Everything that matters.<\/p>\n<p id=\"cs-inline-newsletter-1-privacy\" class=\"cs-inline-newsletter__privacy\">Free to join. Unsubscribe any time.<\/p>\n<p> <i class=\"fa-regular fa-circle-xmark\" aria-hidden=\"true\"\/> <span>Whoops, looks like there was a problem. Please try again.<\/span><\/p>\n<p> <i class=\"fa-regular fa-circle-check\" aria-hidden=\"true\"\/> <span><strong>You\u2019re on the list.<\/strong> Your next Daily Brief is on its way.<\/span><\/p>\n<\/div>\n<\/div>\n<\/aside>\n<p>The second vulnerability, LSB-025, affected the token-payment path used by Ledger\u2019s Exchange application during swaps.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-558617\" src=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba.png\" alt=\"Comparison of Ledger Ethereum app flaws LSB-024 and LSB-025, their affected versions, narrow trigger conditions, and the update to version 1.22.3\" width=\"720\" height=\"1080\" srcset=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba.png 1024w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba-200x300.png 200w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba-683x1024.png 683w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba-768x1152.png 768w\" sizes=\"(max-width: 720px) 100vw, 720px\"\/><img decoding=\"async\" class=\"lazyload aligncenter wp-image-558617\" src=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba.png\" alt=\"Comparison of Ledger Ethereum app flaws LSB-024 and LSB-025, their affected versions, narrow trigger conditions, and the update to version 1.22.3\" width=\"720\" height=\"1080\" srcset=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba.png 1024w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba-200x300.png 200w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba-683x1024.png 683w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/08\/exec-6c174ba4-ad0e-4fcb-ba0e-a3ce5b6edeba-768x1152.png 768w\" data-sizes=\"(max-width: 720px) 100vw, 720px\"\/><\/p>\n<p>Ledger\u2019s app checked the token, quantity, and destination but did not verify that the requested action was actually a payment. A malicious or compromised swap provider could therefore substitute a token approval matching those same parameters and have it signed without an additional device prompt.<\/p>\n<p>The flaw could not create an unlimited approval, switch to another token, or grant permission to an arbitrary address. An approval also does not itself transfer funds, requiring a subsequent transaction before the approved assets could move.<\/p>\n<p>Ledger said it found no evidence that the swap vulnerability was exploited.<\/p>\n<p>The release history raises a separate question. Ledger\u2019s records show the fix for the array-count issue was merged on May 5 and the swap-validation correction on May 25, months before version 1.22.2 was released. Its security bulletins do not explain why those changes were absent from that update.<\/p>\n<p>Ledger defended its broader approach by pointing to updateability as central to hardware wallet security. Its security team said it continuously identifies vulnerabilities through internal research and external bug-bounty programs, then patches them through software releases.<\/p>\n<p>For users, the distinction between the three vulnerabilities is important. Version 1.22.2 fixed the command-interleaving flaw later reproduced by OneKey, while version 1.22.3 is required to address the two additional signing bugs disclosed Aug. 27.<\/p>\n<p>Ledger recommends installing Ethereum app 1.22.3 or later through Ledger Live and verifying the version on the device. Updating the hardware wallet firmware alone does not replace the affected Ethereum application.<\/p>\n<\/div>\n<p>Featured,Hacks,Wallets,ethereum,Ledger,paymentsethereum,Ledger,payments#Ledger #patched #critical #signing #bugs #months #writing #fixes1787920152<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Crypto wallet maker Ledger is urging its Ethereum app users to update again after two signing flaws remained in its previous security release. The hardware-wallet maker published Ethereum app version 1.22.3 on Aug. 25, closing vulnerabilities that could hide operations from a device review or authorize a token approval in place of an expected payment.<\/p>\n","protected":false},"author":1,"featured_media":12509,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[5410,158,31,3859,829,1233,6483,167,4468,1408],"class_list":["post-12508","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ethereum","tag-bugs","tag-critical","tag-ethereum","tag-fixes","tag-ledger","tag-months","tag-patched","tag-payments","tag-signing","tag-writing"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.6 (Yoast SEO v26.6) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Ledger patched critical signing bugs months after writing the fixes - Crypto News: Latest Cryptocurrency News and Analysis<\/title>\n<meta name=\"description\" content=\"Ledger is telling Ethereum app users to update again after two separate vulnerabilities survived its Aug. 13 security release.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.uk.com\/?p=12508\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ledger patched critical signing bugs months after writing the fixes\" \/>\n<meta property=\"og:description\" content=\"Ledger is telling Ethereum app users to update again after two separate vulnerabilities survived its Aug. 13 security release.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.uk.com\/?p=12508\" \/>\n<meta property=\"og:site_name\" content=\"Crypto News: Latest Cryptocurrency News and Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-28T12:29:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/08\/ledger-hidden-signing-paths.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"\u884c\u653f\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u884c\u653f\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12508\",\"url\":\"https:\/\/cryptonews.uk.com\/?p=12508\",\"name\":\"Ledger patched critical signing bugs months after writing the fixes - Crypto News: Latest Cryptocurrency News and Analysis\",\"isPartOf\":{\"@id\":\"https:\/\/cryptonews.uk.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12508#primaryimage\"},\"image\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12508#primaryimage\"},\"thumbnailUrl\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/08\/ledger-hidden-signing-paths.jpg\",\"datePublished\":\"2026-08-28T12:29:12+00:00\",\"author\":{\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf\"},\"description\":\"Ledger is telling Ethereum app users to update again after two separate vulnerabilities survived its Aug. 13 security release.\",\"breadcrumb\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12508#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/cryptonews.uk.com\/?p=12508\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12508#primaryimage\",\"url\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/08\/ledger-hidden-signing-paths.jpg\",\"contentUrl\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/08\/ledger-hidden-signing-paths.jpg\",\"width\":1280,\"height\":720},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12508#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/cryptonews.uk.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ledger patched critical signing bugs months after writing the fixes\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/cryptonews.uk.com\/#website\",\"url\":\"https:\/\/cryptonews.uk.com\/\",\"name\":\"Crypto News: Latest Cryptocurrency News and Analysis\",\"description\":\"Latest Crypto &amp; Bitcoin News\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/cryptonews.uk.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf\",\"name\":\"\u884c\u653f\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g\",\"caption\":\"\u884c\u653f\"},\"sameAs\":[\"http:\/\/demo3.aiwalls.com\/coinbase\"],\"url\":\"https:\/\/cryptonews.uk.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Ledger patched critical signing bugs months after writing the fixes - Crypto News: Latest Cryptocurrency News and Analysis","description":"Ledger is telling Ethereum app users to update again after two separate vulnerabilities survived its Aug. 13 security release.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.uk.com\/?p=12508","og_locale":"en_US","og_type":"article","og_title":"Ledger patched critical signing bugs months after writing the fixes","og_description":"Ledger is telling Ethereum app users to update again after two separate vulnerabilities survived its Aug. 13 security release.","og_url":"https:\/\/cryptonews.uk.com\/?p=12508","og_site_name":"Crypto News: Latest Cryptocurrency News and Analysis","article_published_time":"2026-08-28T12:29:12+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/08\/ledger-hidden-signing-paths.jpg","type":"image\/jpeg"}],"author":"\u884c\u653f","twitter_card":"summary_large_image","twitter_misc":{"Written by":"\u884c\u653f","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/cryptonews.uk.com\/?p=12508","url":"https:\/\/cryptonews.uk.com\/?p=12508","name":"Ledger patched critical signing bugs months after writing the fixes - Crypto News: Latest Cryptocurrency News and Analysis","isPartOf":{"@id":"https:\/\/cryptonews.uk.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.uk.com\/?p=12508#primaryimage"},"image":{"@id":"https:\/\/cryptonews.uk.com\/?p=12508#primaryimage"},"thumbnailUrl":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/08\/ledger-hidden-signing-paths.jpg","datePublished":"2026-08-28T12:29:12+00:00","author":{"@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf"},"description":"Ledger is telling Ethereum app users to update again after two separate vulnerabilities survived its Aug. 13 security release.","breadcrumb":{"@id":"https:\/\/cryptonews.uk.com\/?p=12508#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.uk.com\/?p=12508"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptonews.uk.com\/?p=12508#primaryimage","url":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/08\/ledger-hidden-signing-paths.jpg","contentUrl":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/08\/ledger-hidden-signing-paths.jpg","width":1280,"height":720},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.uk.com\/?p=12508#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.uk.com\/"},{"@type":"ListItem","position":2,"name":"Ledger patched critical signing bugs months after writing the fixes"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.uk.com\/#website","url":"https:\/\/cryptonews.uk.com\/","name":"Crypto News: Latest Cryptocurrency News and Analysis","description":"Latest Crypto &amp; Bitcoin News","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.uk.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf","name":"\u884c\u653f","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g","caption":"\u884c\u653f"},"sameAs":["http:\/\/demo3.aiwalls.com\/coinbase"],"url":"https:\/\/cryptonews.uk.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts\/12508","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=12508"}],"version-history":[{"count":0,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts\/12508\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/media\/12509"}],"wp:attachment":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=12508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=12508"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=12508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}