Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed
ID: 2befa461-abd1-5871-82c7-2379fa851689
STIX ID: report--2befa461-abd1-5871-82c7-2379fa851689
Feed Name: The Cyber Express
A disputed clear‑signing vulnerability in Ledger’s Ethereum app was reported by security firm TestMachine, which said its AI scanner validated a race-condition attack that could display one transaction on-device while preparing another for signing. Ledger’s CTO and internal Donjon team say the issue was independently identified and patched two weeks before public disclosure, but GitHub release tags and a formal advisory are missing, no verified fund theft has been reported, and the disclosure timeline remains unresolved.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
