Ledger 发布安全公告披露漏洞,涉及屏幕确认过程中签名参数可被替换

Ledger 发布安全公告披露漏洞,涉及屏幕确认过程中签名参数可被替换

2026-08-28 08:59

ChainThink 消息,8 月 28 日,据官方公告,Ledger 发布安全漏洞披露。

该漏洞允许主机在屏幕确认尚未完成时插入新 APDU 指令,导致设备显示内容与最终签名参数不同步,用户可能在不知情下签署被篡改的路径、金额或地址。

漏洞属于应用 SDK 层面,设备操作系统与固件本身不受影响。修复已随 SDK v26.6.1 版本发布,用户需通过 Ledger Live 更新相关应用,仅升级固件无法解决。

第三方开发者已基于新 SDK 重新构建应用。

Disclaimer: Contains third-party opinions, does not constitute financial advice

Recommended Reading

NVIDIA attracts $85 billion in investor demand during massive bond issuance

06-16
NVIDIA attracts $85 billion in investor demand during massive bond issuance

Ethereum surges over 10% in 24 hours, currently priced at $1,841.31

06-16
Ethereum surges over 10% in 24 hours, currently priced at $1,841.31

Amazon announces a multi-billion dollar investment in Missouri to build a data center campus, expected to create over 400 long-term positions

06-16
Amazon announces a multi-billion dollar investment in Missouri to build a data center campus, expected to create over 400 long-term positions

Binance Platform's SpaceX Perpetual Contract Trading Volume Surpasses $9 Billion, Capturing Over 60% Market Share

06-16
Binance Platform's SpaceX Perpetual Contract Trading Volume Surpasses $9 Billion, Capturing Over 60% Market Share

Binance platform XLM/USDT short-term spike down to $0.17, now recovered to $0.225

06-16
Binance platform XLM/USDT short-term spike down to $0.17, now recovered to $0.225

Trump: The Strait of Hormuz has been fully reopened as of Friday, and all agreements have been signed

06-16
Trump: The Strait of Hormuz has been fully reopened as of Friday, and all agreements have been signed

SlowMist: Aztec Connect Contract Hacked for $2.19 Million Due to ZK-Rollup L1/L2 State Boundary Vulnerability

06-15
SlowMist: Aztec Connect Contract Hacked for $2.19 Million Due to ZK-Rollup L1/L2 State Boundary Vulnerability