🚨Every Ledger running the Ethereum app is vulnerable to signature substitution
A malicious dApp with WebHID access could race an APDU during your transaction review and swap the tx being signed while the device still shows the original
Here's what you need to know: