Ledger Identifies SDK Vulnerability Enabling Unauthorized Modification of Transaction Signing Parameters

AI مارکیٹ کا خلاصہ
Ledger disclosed an application SDK vulnerability allowing APDU injection before on-device confirmation completes, creating a risk that users sign altered parameters despite correct screen display. While OS/firmware are unaffected, remediation requires updating wallet apps via Ledger Live and third-party rebuilds using SDK 26.6.1. The headline raises near-term self-custody and transaction-integrity concerns, which can weigh on crypto risk sentiment broadly.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+0.97%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
On Aug. 28, hardware wallet provider Ledger identified a security vulnerability within its application SDK layer, as reported by ChainThink. The flaw allows a host to inject additional APDU commands before on-screen confirmation is finalized, potentially creating a discrepancy between the data displayed on the device and the actual parameters used for signing. This could lead users to inadvertently approve modified derivation paths, transaction amounts, or recipient addresses. Ledger clarified that the issue does not affect the device's operating system or firmware. A critical fix has been released in SDK version 26.6.1. To mitigate the risk, users must update their specific blockchain applications through Ledger Live, as firmware updates alone are insufficient. Third-party developers have already begun rebuilding their applications using the patched SDK to ensure user security.