Today, we’re launching Azimuth Points + Leaderboard.
Security Researchers & Auditors can now earn points for validated findings, climb the leaderboard, and turn their contributions into more access to Azimuth.
Season 1 starts today. On September 30, we’ll snapshot the
Ledger published the GitHub release for Ethereum app v1.22.2 today
Release notes, in full: “Security issues.”
That is not a summary either.. That is the entire body of the release notes.
Update via Ledger Live now, then read on. This one matters. 🧵
We shared this to inform folks to stay safe.
Agree with this CTA: If you stick to dApps you know and trust, and always carefully review what you’re signing then you are fine
We are still waiting on the release from @Ledger. That should resolve this completely
This security vulnerability affecting @Ledger devices can impact PulseChain users and EVM users in general.
This is known as signature substitution. Malicious dApps can potentially bypass clear signing and present a fake signing message, which could put Ledger hardware wallets
🚨Every Ledger running the Ethereum app is vulnerable to signature substitution
A malicious dApp with WebHID access could race an APDU during your transaction review and swap the tx being signed while the device still shows the original
Here's what you need to know: