Flash News
Ledger disclosed the details of the LSB 023 loophole and the user needed to update the application repair
Ledger disclosed the details of the LSB 023 security breach, which was partially based on the application of the Legger Security SDK build to still receive the APDU command during screen confirmation, resulting in inconsistencies between the screen display parameters and the final signature parameters. Ledger has released the Ledger Security SDK v26.6.1 and re-engineered the application, the user is required to update the application through Ledger Live, and there is no evidence that the loophole is actually being used。
