Interestana
Home/News/Ledger Denies Hack, Cites Patched Ethereum App Vulnerability
Decrypt2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Ledger Denies Hack, Cites Patched Ethereum App Vulnerability

Ledger Denies Hack, Cites Patched Ethereum App Vulnerability

Ledger has refuted claims of a hack, stating that a vulnerability demonstrated by cybersecurity firm OneKey, which allowed an outdated Ethereum application to sign a transaction different from what was displayed on a Ledger device, had already been patched prior to any potential exploit. OneKey's demonstration, shared on March 19, 2024, highlighted a scenario where a user might approve a malicious transaction without realizing it due to the discrepancy between the transaction presented to the user and the one ultimately signed by the hardware wallet. This particular vulnerability was identified within an outdated version of the MyEtherWallet (MEW) Ethereum application, which is a third-party application that interfaces with Ledger hardware wallets. Ledger emphasized that the core security of its hardware wallets remained intact and that the issue was specific to the outdated software of a connected application. The company clarified that the vulnerability was addressed and the relevant software was updated before any malicious actors could leverage it. The demonstration by OneKey aimed to educate users about the importance of keeping both their hardware wallet firmware and connected applications up-to-date to ensure maximum security. Ledger's statement underscored its commitment to user security and its proactive approach to addressing potential threats. The company also reiterated its recommendation for users to always verify transaction details meticulously on their Ledger device's screen before confirming any operation, regardless of the application being used. This incident serves as a reminder of the layered security approach required in the cryptocurrency space, where the security of hardware wallets, software applications, and user vigilance all play critical roles in protecting digital assets. Ledger's response aimed to prevent misinformation and reassure its user base about the integrity of its products. The company's communication strategy focused on transparency, detailing the nature of the vulnerability and the steps taken to mitigate it, thereby reinforcing trust in its security infrastructure. The incident did not involve a breach of Ledger's internal systems or a compromise of private keys stored on its devices. Instead, it focused on a potential user interface confusion within a third-party application that could have been exploited if not for prior patching.

Original source — read the full reporting at the publisher:

Read on Decrypt

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next