Ledger Security Bulletins

Technical details of past security issues, their potential impact and available patches or workarounds.

Ledger believes in better security through openness. If you believe that you have discovered a vulnerability, please report it through the bug bounty program.

ID Title Date
LSB 021 Ledger Security Bulletin 021 Missing parameter validation during MCU firmware update
LSB 020 Ledger Security Bulletin 020 Ledger Live incorrectly parses some EIP-712 messages
LSB 019 Ledger Security Bulletin 019 Invalid addresses for certain miniscript policies
LSB 018 Ledger Security Bulletin 018 Invalid command processing on HSM firmware
LSB 017 Ledger Security Bulletin 017 Keycard bypass on Ledger HW.1
LSB 016 Ledger Security Bulletin 016 Length-extension attack on SCP
LSB 015 Ledger Security Bulletin 015 TX data of unsupported crypto assets are not displayed by the Ethereum app 1.6.0
LSB 014 Ledger Security Bulletin 014 Path derivation too permissive in Bitcoin derivative apps
LSB 013 Ledger Security Bulletin 013 JTAG/SWD Protocols Enabled on STM32WB55 Unsecured Processor
LSB 012 Ledger Security Bulletin 012 Incorrect BTC balance in Ledger Live with RBF UTXOs
LSB 011 Ledger Security Bulletin 011 XRP account misuse and transaction malleability
LSB 010 Ledger Security Bulletin 010 Massive transaction fees in BTC app and derivative
LSB 009 Ledger Security Bulletin 009 Monero funds lock-up
LSB 008 Ledger Security Bulletin 008 Monero private key retrieval
LSB 007 Ledger Security Bulletin 007 Monero private key retrieval
LSB 006 Ledger Security Bulletin 006 OLED screen side-channel vulnerability
LSB 005 Ledger Security Bulletin 005 MCU Bootloader verification bypass
LSB 004 Ledger Security Bulletin 004 Bitcoin change address injection
LSB 003 Ledger Security Bulletin 003 Isolation vulnerability
LSB 002 Ledger Security Bulletin 002 Supply chain attack
LSB 001 Ledger Security Bulletin 001 Padding oracle attack on SCP

Note: these security bulletins are inspired by Qubes Security Bulletins but aren't related in any way.