2/2 Ledger addressed the issue in Ethereum app v1.22.3+. Users should update before relying on Clear Signing for affected flows.
🧪 Reproducing the PoC? Use a separate test device with a fresh, disposable seed and no funds.
1/2 ⚠️ One action displayed. 257 authorized ⚠️
Our full write up is live: Signature overflow attacks on Ledger.
A Clear Signing bug broke a critical security property: What you see is what you sign.
🔎 Technical details + PoC:
bitfinding.com/blog/signatur…
2/2 A compromised frontend could make the trusted screen omit actions still covered by the signature.
We demonstrated the Safe attack end to end and confirmed the same display/signature divergence in Aave and Morpho multicall flows.
PoC coming soon. In the meantime, update.
1/2 We helped Ledger identify and fix a High-severity Clear Signing vulnerability.
Ethereum app 1.19.0–1.22.2 is affected. Update to 1.22.3+.
Our advisory:
bitfinding.github.io/publica…
If you use Ledger for Ethereum, please update the Ethereum-app to v1.22.3. This is a new release.
Go update your Ledger. Again.
However, in a world where everyone gets access to the latest models at the same time and agents are watching everyone and everything, unreleased fixes or vulns can’t sit in the open until Patch Tuesday.
We acknowledged and applaud that @Ledger is upping their offensive security with the latest LLMs to find these vulnerabilities before the bad guys do
The trusted screen can be tricked into showing one message while the device authorizes a completely different signature (WYSIWYS). That breaks one of the main security purposes of the hardware. Multiple bugs found by @DonjonLedger and others have the same effect
This exploit is similar to our not-WYSIWYS attack reported in March. We followed responsible disclosure and are waiting for the fix to be widely adopted before dropping the POC
Any funds recovered during our reorg experiments have already been returned to their owners. More research and technical write-ups are coming.
Big thanks to @thedaofund, @quantstamp, @wintermute_t, and @Giveth for supporting our work.
We also reported security issues affecting a widely used hardware wallet. We’re coordinating with the relevant team and will publish the technical details when it’s appropriate to disclose them responsibly.
Research update: we’ve been heads down on several projects we’ll be sharing soon. One is our investigation into reorgs, orphans, and cross-chain execution triggered before confirmation. Several bridges are in scope, and we’re sharing findings with their teams privately.
Huge thanks to @giveth and everyone involved to make this happen.
Thanks to this initiative we can spend more time in public good projects that benefit the whole ecosystem.
TheDAO's Ethereum Security QF Round matching funds have officially been distributed 🛡️
What started as a 500 ETH matching pool from @thedaofund ultimately grew to 638 ETH+ thanks to support from across the ecosystem.
134 projects have now received funding to continue their work strengthening Ethereum security.
A huge thank you to every donor, contributor, and project that made this round possible.
It's great having @DecurityHQ securing the blockchain at the milliseconds game. Competition in this space is what will make the last line of defense stronger!
Replying to @DecurityHQ
4/ Balancer V2 reached 54% of funds-at-risk in minute one, 93% by minute five.
Even at that speed, @BitFinding's whitehat bot intercepted the attacker in the very next block - 12 seconds after the first malicious tx. ~$1M returned to Balancer DAO.
This is the kind of security crypto needs more of: technical, proven, and built for the whole ecosystem.
Today it is only rewarded through bounties. @Giveth lets the ecosystem fund it proactively.
With QF, even $10 can carry far more weight.
qf.giveth.io/project/bitfind…
Our whitehat bot fuzzes the blockchain on real time, detecting and intercepting exploits.
As an example, only during the Balancer attack, we secured >$1M in a single block.
We’re raising on @Giveth QF to scale our public-good infrastructure.
🚨 Exploit Alert:
Bad error handling attack
Chain: Ethereum
Loss: 17 WBTC ($1.3M)
TX: 0x770bc9a1f7c32cb63a5002b9ceb5c7994cd3af0fc6b2309cb32d3c46f629daa0
etherscan.io/tx/0x770bc9a1f7…
Starting in 5
Happening today: @BitFinding’s founders are joining @Crypto_ISAC to walk through how their on-chain Exploit Interception Agent responded to the recent Balancer exploit in real time.
⏰ Today, 9 AM PT/ 12 PM ET
🔗 Last chance to register: buff.ly/5FhBzzK
Join us, we'll present what happened during the 2 hours following the initial Balancer attack, including the malicious and whitehat transactions in all the chains
DeFi defense at block speed, not alert speed. ⚡️
Join @Bitfinding founders as they unpack the Balancer composable stable pool exploit and how on-chain interception stopped it in its tracks.
Brought to you by @Crypto_ISAC in collaboration with @Bitfinding.
📅 Dec 18 • 12–12:45 PM ET
🔗 Register: buff.ly/YsAXH6s