Ledger Wallet Vulnerability; Users Must Update Ethereum App to Version 1.22.2
A security vulnerability has been identified in the Ethereum application of Ledger hardware wallets that could allow a malicious dApp to sign a transaction different from what is displayed on the device screen under certain conditions. Ledger has released version 1.22.2 of the Ethereum application to address this issue, and users are urged to install it as soon as possible.
According to Mihan Blockchain, this vulnerability was related to the way simultaneous signature requests were managed. In the attack scenario, the details of the original transaction were still displayed on the device screen, but a second request could replace it in memory, ultimately sending different data for signing to the device.
How Did the Vulnerability Work?
According to a report by the security company TestMachine, exploiting this bug required a dApp with WebHID access, a feature that allows certain web applications to communicate directly with hardware devices.
In this scenario, the attacker could send a second signature request while the user was reviewing a transaction. This request would replace the previous transaction data in memory without initiating a new review process. As a result, the user would still see the initial transaction information on the display but would sign the replaced data upon selecting the confirm option.
TestMachine also stated that it reproduced this scenario on the Ledger Flex.
What Changes Did Ledger Make to Fix the Issue?
The recorded changes in Ledger's official code indicate that the company added two security controls to prevent the attack. First, the application no longer allows a new signature request to interrupt the review process of an ongoing transaction. Second, when receiving a confirmation command, the current status of the signing process is checked, and if it does not match the expected status, the request will be rejected.
These fixes have been implemented in version 1.22.2 of the Ethereum application, which was released on August 12. However, TestMachine claims that this version has not yet been fully made available to users.
According to TestMachine, due to the use of shared code, this flaw could also affect the Nano X, Nano S Plus, Stax, and Apex models. The official file for version 1.22.2 also lists these models alongside Ledger Flex as target devices for the Ethereum application.
Ledger has not yet specified which was the first vulnerable version of this application. Therefore, it is unclear how many previous versions contained this bug.
Discrepancy Between Ledger and TestMachine on Discovering the Vulnerability
Charles Guillemet, Chief Technology Officer of Ledger, announced on August 23 that Ledger's internal security team, Ledger Donjon, had identified this bug before TestMachine contacted the company through its bug bounty program.
Guillemet stated that this team had identified and fixed the issue in some "transparent signing" processes about two weeks before his statement. In contrast, TestMachine claimed that the Azimuth system identified this vulnerability and shared its findings with Ledger, confirming their validity.
Despite this discrepancy in narratives regarding the timing and manner of discovering the vulnerability, both parties have confirmed the existence of the problem and its fix in the application code.
It is worth noting that, so far, there have been no confirmed cases of exploitation of this vulnerability in the real world, theft of user assets, or extraction of private keys reported. However, since the flaw directly relates to the transaction verification and signing process, updating the application is of particular importance.
Ledger users should check the version of the Ethereum application on their device and upgrade it to 1.22.2 if they are using an older version. Ledger has also advised users to keep not only the Ethereum application but also the device's operating system, other applications, and related client software updated to the latest version.
Additionally, this vulnerability differs from another security flaw previously reported in Ledger's native Zilliqa application and is unrelated to the 2023 attack on Connect Kit.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

When Agents Learn to 'Collude': As AI Becomes Smarter, How to Define Safe Boundaries?

Is AI Breaking the Mathematical Fortress? Is the 'Mathematical Apocalypse' of Cryptocurrency Just a False Alarm?

XRP Ledger Activates Permission Delegation Feature

XDP Coin Price Drops Below $0.02 After Its September Listing: What Is Behind Doppler Finance's Post-Launch Slide?

Another Michael Saylor: An Engineer, Entrepreneur, and Sci-Fi Enthusiast's Thirty Years

National Day Holiday DeFi News Review: Hyperliquid Plans to Enter Options Market, Uniswap Pilots Compliant Liquidity Architecture

US Moves $470 Million in Crypto: What Does This Signal?

Researcher Calls for Crypto Industry to Enter 'Bunker Mode' to Protect Against AI and Quantum Attacks

$2.39 Billion Investment in Bitcoin ETFs, Spot Demand Remains Negative

Elon Musk Net Worth Trillion Dollars: Will He Be a Trillionaire Again?

What Does a Rising VIX Mean for the Stock Market? A 2026 Investor Guide

Why Is VIX Rising Today? What VIX Means for Stocks and Bitcoin

The Real Estate Market Is Dead In Spain. Long Live Bitcoin.

Why Hyperliquid's Prediction Market HIP-4 Can't Keep Up with Polymarket?

Why Is iExec RLC (RLC) Crypto Rising Today? Privacy Demand, Multichain Migration, and the Volume Test
Why is iExec RLC rising today? Examine RLC volume, confidential-computing utility, token supply, bridge migration, and the adoption evidence to watch.

How to Join WEEX Alpha Suite at TOKEN2049 Singapore 2026: Dates, Location and Registration
Find out how to join WEEX Alpha Suite at TOKEN2049 Singapore 2026, including the event dates, location, registration details, and who can attend.

Bitcoin Fear and Greed Index: How It Works

Samsung Electronics Files Patent for Smart Contract Cryptocurrency Wallet

Bitcoin: Strategy Acquires Another 334 BTC, Raising Its Reserve to 848,000

SNDK Stock Fell 3.8% After a 650% Rally: Does a Single-Digit P/E Make Sandisk Cheap or Just Cyclical?

Oil Futures Hold Above $100 After Houthis Claim Aramco Attacks: What Is Confirmed and What Is Not

MSTR Stock Slips After Strategy Buys Just 334 Bitcoin: Why It Spent More on Preferred Shares Than on BTC

INTC Stock Drops After TSMC Terafab Talks: Is Intel's Biggest Outside Endorsement at Risk?

Who Will Aave Hand Its Brand Over To? The DAO Asset Ownership Dispute Behind the Foundation Proposal

Will Bitcoin (BTC) Go Back Up in 2026? How to Tell a Real Recovery From a Short-Covering Bounce
Will Bitcoin go back up in 2026? Learn how spot demand, ETF flows, crypto liquidity, futures positioning and macro conditions shape a real BTC recovery.

Hyperliquid's Perpetual Futures Listed on Bloomberg Terminal, Increasing Institutional Investor Interest

NSE Stock Price Hits a New Low After IPO: Can National Stock Exchange Shares Recover?
National Stock Exchange of India shares traded near ₹1,741 on October 5, close to a post-listing low of about ₹1,735 and roughly 2.5% below the ₹1,785 IPO price. The stock has now spent more than a week under its issue price, and a recovery depends on retail demand, derivatives volumes and the broader Indian market.

Trump Creates Super Intelligence Force: What Changes in the AI Race

Home-jacking crypto: they threaten to kill a pregnant woman's baby in England









