The hardware wallet manufacturer, Ledger, responded to a loophole in the application of the Taifu. The company disclosed that the issues discussed in recent days appeared in the old version of Ethereum App 1.22.1, that the repairs had been online before OneKey published the results of the experiment and that there was no evidence that the loophole had been used against users in the real environment.
OneKey founder, Wang One Stone, stated on platform X on August 27 that his security team, Anzen, had reproduced a “trade replacement” attack in an experimental environment. According to its description, the loophole is related to the competitive conditions between the presentation of the logic of the transaction and the bottom trading buffer. If the assailant has control over the communication between the equipment and the host, it may replace the signature to be signed when the user checks a normal transaction.
We need to control the communication link first.
In a security notice issued the same day, Ledger indicated that the problem could lead to a transaction on the device screen, but the actual signature was another transaction. However, there is a clear premise for an attack: the assailant must first control the communication link between the hardware wallet and a computer or mobile phone, for example, through malicious software, broken wallet applications or the intervention of malicious websites.
Charles Guillermomet, the company's chief technical officer, stated that reruning a repaired loophole on the old version was not equivalent to “Ledger Black”. He states that the company discovered the problem in an internal security process and completed the repairs in Etherum App 1.22.2, released on 13 August, earlier than the oneKey public related tests.
The repairs were completed in two steps in August.
Ledger discloses that the first step was to introduce Etherum App 1.22.2 on 13 August, with additional protection. The second step was to restore the bottom of Secure SDK 26.6.1 on 21 August and to re-engineer related applications accordingly. The company currently recommends that the user upgrade to a version of 1.22.3 or more, which also fixes another trade display gap.
- Etherum App 1.22.1
- 1.22.2 Rehabilitation released on 13 August
- 1.22.3 The current recommended version
The company says no real evidence of the attack.
Ledger states that to date no evidence has been found that the loophole was used outside the laboratory. Guillermomet also stated that no user had been hacked because of the problem and that the available information indicated that the recurrence was a laboratory test rather than a new attack found in the real world.
According to Donjon, another Ledger security research team on platform X, the incident also indicated that hardware wallets required software upgrades. The team stated that the software was not uncommon and that the key was the ability of the manufacturer to quickly restore the sold equipment when it discovered the problem.
Additional information:Earlier this month, Coldcard's isolated hardware wallet users were exposed to the theft of more than $130 million bitcoin. Ledger Senior stated at the time that this was a warning for the entire hardware wallet industry.
