A recently highlighted vulnerability in Ledger’s Ethereum application for its hardware wallets has drawn attention in the cryptocurrency community. The issue involved a race condition in certain clear-signing processes. In these flows, users review human-readable transaction details on the device screen before approving them.
Security researchers described how a malicious decentralized application with appropriate access could send competing commands during the review window.
This potentially allowed the data held in memory for signing to be replaced without refreshing the on-screen display.
There’s some FUD circulating about Ledger signers, pushed by a “smart contract security” company claiming a vulnerability in the Ledger…





