Ledger Wallets Found Vulnerable to Signature Substitution Attack

iconBitMedia
Share
AI summary iconSummary
AI + crypto news: According to BitMedia, Ledger wallets were found to be vulnerable to a signature substitution attack. The flaw, detected by an AI-based system, affected the transparent signing feature. Ledger patched the issue two weeks before public disclosure. Users with updated firmware and apps are protected. TestMachine researchers warned that attackers could modify transaction data during review. The vulnerability impacts the Nano X, Nano S Plus, Stax, and Apex models. Ledger urged users to update their software and firmware. This vulnerability underscores the risks of blind signing, as smart contract actions may not always be clearly visible. As of August 24, no confirmed thefts have been reported.

The error was discovered by the Ledger Donjon team using an AI-powered vulnerability detection system, according to a senior executive. The issue affected the transparent signature feature, which is designed to display transaction details—such as the amount, address, and smart contract actions—on the screen before the user confirms them.

Ledger deployed the patch approximately two weeks before it became publicly known. Developers assured users that those with updated firmware and apps are protected. As of August 24, no confirmed cases of theft related to this vulnerability have been reported.

Researchers at TestMachine, using the AI tool Azimuth, reported that attackers could replace transaction data and send a competing, desired command at the moment when the Ledger user is still reviewing the original transaction. As a result, the device could display one transaction while signing another. TestMachine stated that the vulnerability affects several hardware wallet models, including the Nano X, Nano S Plus, Stax, and Apex.

Ledger itself has not published a detailed technical description of the vulnerability or a list of affected wallet versions. Ledger’s CTO stated that TestMachine contacted Ledger only after the company had released the fix. He called TestMachine’s claim about the issue’s relevance “fearmongering to attract attention.” In turn

TestMachine analysts stated that they shared their research findings with Ledger and declined the reward.

Ledger representatives recommend wallet owners to update the Ledger Wallet software, device firmware, and the installed Ethereum application. Updating only the desktop or mobile interface may not be sufficient if the application on the device itself is outdated. Users should verify transaction details directly on the device’s secure screen. Blind signing can be dangerous, as the device does not always display every smart contract action in a readable format, Ledger experts warned.

Previously anonymous blockchain researcher ZachXBT suggested followers to stop using Ledger hardware wallets. The blockchain investigator fears that too-frequent updates change the interface and sometimes disrupt the device’s basic functions.


Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.