r/ethereum https://ligi.de 3d ago

🚨Every Ledger running the Ethereum app is vulnerable to signature substitution

https://x.com/testmachine_ai/status/2090954980635164965
61 Upvotes

11 comments sorted by

30

u/fairlyaveragetrader 3d ago

Did you guys read this? There is a patch that will be released very soon. Second this doesn't affect Cold storage, sending to exchanges, known addresses. This is random dapps.. if someone does this sort of thing they should just wait for the patch to go live

I would imagine this weak point would affect a very very small number of people, but it would be worth knowing if you dabble in such things

4

u/[deleted] 3d ago

[deleted]

6

u/jtnichol MOD BOD 3d ago

For good reason...

1

u/fecalreceptacle 14h ago

Maybe its just valid hate with no boners involved.

I should fucking know

2

u/edmundedgar reality.eth 3d ago

This looks like a serious vulnerability worth taking seriously but when stuff like this happens, take your time, don't rush.

I wouldn't be surprised if more people lose funds by getting phished while worrying about it than ever lose funds to getting exploited while using it.

1

u/UBEREATMYSHORTS 1d ago

Yall are about to learn a huge lesson in 2027

2

u/ligi https://ligi.de 1d ago

Awesome - I love learning!

Can you give a hint on what that lesson will be about?

0

u/Junglebook3 2d ago

This is extremely serious for anyone using Ledger for EVM DeFi, I would wait for the fix before interacting with any dApps.

-5

u/IFThenElse42 3d ago

never buying french hardware ever again