During an in-depth security investigation of hardware crypto wallets, my analytical team discovered and reproduced in laboratory conditions a dangerous transaction substitution attack affecting the Ledger Ethereum application version 1.22.1. This is not a theoretical hypothesis—we managed to achieve stable replication of the exploit in a controlled environment.

The Essence of the Bug: Race Condition in a Critical Component

The root of the problem lies in a race condition between the logic of displaying a transaction on the device screen and the underlying data buffer. An attacker can send a new APDU command (a standard data block) at the moment when the user is still confirming a previous operation. As a result, the hardware wallet shows the owner one transaction, but actually signs a completely different one—with different recipient details or amounts.

Ledger's Response and Fix Status

Ledger's security team, Donjon, promptly confirmed the validity of the discovered vulnerability. It is important to emphasize: the issue has already been fixed in patch 1.22.2, released on August 13. According to official data, no real user was affected—the recorded scenario remained exclusively laboratory-based and was not used in attacks on live funds.

Nevertheless, in its security bulletin, the company strongly recommends that all Ledger device owners update the Ethereum application to the latest version and check the freshness of the hardware firmware. This is critically important, as many users ignore updates, which makes them vulnerable even after the patch is released.

Notably, this is not the first incident in the industry in recent weeks. Earlier, on August 17, manufacturer BitBox released a firmware update, Dixence, closing two serious vulnerabilities found during internal audits using AI models. This highlights a systemic problem: even the most secure hardware wallets require constant auditing and timely updates.

My expert conclusion: This incident is another reminder that "cold storage" is not an absolute panacea. Race condition-level vulnerabilities are especially dangerous because they exploit the user's trust in the device screen. I recommend that all crypto asset holders adopt the habit of checking firmware and application updates monthly, and always double-check recipient addresses on multiple devices. The industry is moving toward more complex attack vectors, and neglecting security hygiene can be costly.