Back En.Bloomingbit Ledger Patches Ethereum App Signing Flaw, Says Users on Latest Version Are Protected
Ledger has patched a security flaw affecting part of the signing process in its Ethereum app.
Wu Blockchain reported on August 24 that Ledger Chief Technology Officer Charles Guillemet said the company's security research team, Ledger Donjon, found the vulnerability in part of the app's clear-signing process and completed a fix two weeks ago.
Clear signing lets users review transaction details, including the recipient and amount, in a human-readable format before signing a blockchain transaction. The flaw was found in some signing flows that use that feature.
Users who keep their Ledger device firmware and related applications updated to the latest versions are protected from the vulnerability, Guillemet said.
He also criticized the way an external security firm disclosed the flaw. Guillemet said a company that identified itself as a smart-contract security firm disclosed the vulnerability after Ledger had completed the patch rollout and then suggested the issue had not been resolved.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
