Ledger states that the loophole affecting the clear signature process in the area of Taifung has been repaired prior to public disclosure by external security companies. Charles Guillermomet, the company ' s chief technical officer, stated on 23 August that the users of the currently updated solids and applications were protected. As at 24 August, there had been no confirmed cases of theft of funds directly related to this loophole.

The purpose of a clear signature is to display the transaction amount, address and smart contract operation on the device screen in a readable form before the user can confirm it, rather than showing only hard-to-identify Hash values. This question concerns the communication process between the Ledger Ether application and the external application.

Bugs affect signature verification

The security company TestMachine stated that malicious applications might have sent another competition order while the user was still looking at the original transaction. According to them, this could lead to a transaction on the device screen, but the actual intention was to sign another operation.

The researchers have cited, for example, the possibility that the attackers could replace the originally restricted transaction with a broader token authorization. Ledger acknowledges that the loophole exists in a “partly clear signature process”, but does not publish a complete technical description, a list of affected versions or a separate security notice.

There's a difference in the time for disclosure.

Guillermomet states that the Ledger Internal Security Research Team, Donjon, discovered the problem using a system of artificial intelligence loopholes and completed the rehabilitation deployment approximately two weeks before he spoke. He also states that the patch was online when TestMachine contacted the leakage reward scheme.

TestMachine indicated that the discovery had been shared and validated with Ledger but that it had refused to receive the reward. The differences between the parties focused mainly on the order of disclosure and whether the issue remained unrecovered at the time of the public communication.

User needs to update solidware and applications simultaneously

Ledger reminds users that wallet software, equipment solids and hardware-based Ether application should be updated simultaneously. Only the desktop or mobile interface is updated does not mean that the application running in the device has been updated simultaneously.

The company also recommended that users re-check the transaction details on the equipment security screen. At the same time, Ledger suggests that blind signatures remain at a high risk because the equipment cannot convert all smart contract operations to readable content.

Additional information:The ETA previously advanced the readable trade summary through the ERC-7730 standard, and Ledger was involved in the development of the programme and the follow-up maintenance work was transferred to the ETA Foundation.