# Patch Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Patch", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

Transaction Substitution Vulnerability Discovered in Ledger's Ethereum Application

A vulnerability involving transaction substitution has been identified and confirmed in the Ethereum application for Ledger hardware wallets. The issue was a race condition between the transaction data displayed on the device's screen and the buffer holding the actual transaction data. This flaw allowed a malicious actor to overwrite a pending transaction while the user was reviewing a legitimate one on the display, potentially leading to the signing of an unseen transaction. The vulnerability was independently discovered by multiple parties. On August 22, 2026, researcher TestMachine disclosed it after detection by the Azimuth scanning tool. Later, on August 27, OneKey's founder Yishi Wang announced his team had successfully replicated the attack in a lab environment on app version 1.22.1. Ledger's security team, Donjon, responded that no real-world exploits or user losses occurred. They stated the flaw was internally identified and patched in Ethereum app version 1.22.2, released on August 13, 2026—prior to the public disclosures. An update to the underlying Ledger Secure SDK (v26.6.1) followed on August 21. Official security bulletin LSB 023, published August 27, details the vulnerability as residing in the SDK's I/O handling. While there is minor public discrepancy over whether version 1.22.2 or 1.22.3 fully resolved the issue, all parties strongly urge users to update their Ethereum application to the latest version via Ledger Live. The incident highlights a critical security principle: the safety of a hardware wallet depends on the entire chain of components—firmware, SDK, and applications—with a flaw in any link compromising the overall system.

cryptonews.ru08/28 09:26

Transaction Substitution Vulnerability Discovered in Ledger's Ethereum Application

cryptonews.ru08/28 09:26

Unbelievable! Cosmos Publishes High-Risk Patch Without Prior Notice, Hackers 'Empty' Project Treasuries First

A series of preventable security attacks recently struck multiple Cosmos ecosystem blockchains—including MANTRA, TAC, KiiChain, and Nesa—all built using the Cosmos EVM module. Attackers drained protocol treasury wallets and dumped the stolen tokens, causing assets like KII, TAC, and NES to plunge over 90% within hours. The root cause was a critical security vulnerability. On August 19, Cosmos Labs publicly released version v0.7.2 on GitHub, containing an urgent security patch. However, they failed to privately notify or coordinate with the dependent project teams beforehand, leaving the exploit details openly accessible. This allowed malicious actors to study and execute attacks before most teams could respond. Affected projects like KiiChain criticized Cosmos Labs for bundling the critical fix with unrelated updates and not treating it with the necessary urgency, such as recommending chains to pause operations. The exploit combined three upstream flaws in the Cosmos EVM module, affecting any chain with vesting accounts enabled. Despite some teams, like MANTRA, identifying the issue early, attacks continued for days. Nesa’s token crashed 94% before the team halted its chain. Cosmos Labs eventually issued a belated response, advising chains to pause, but widespread criticism highlighted a severe failure in vulnerability disclosure, patch coordination, and ecosystem communication. This incident underscores deep flaws in Cosmos's security auditing, cross-chain coordination, and emergency response systems, further damaging confidence in an ecosystem already facing significant project departures and declining traction.

marsbit08/25 02:51

Unbelievable! Cosmos Publishes High-Risk Patch Without Prior Notice, Hackers 'Empty' Project Treasuries First

marsbit08/25 02:51

Besu Patches Vulnerabilities in 5 Components: What Node Operators Need to Know

The Ethereum client Besu, developed by the Hyperledger community, has patched five security vulnerabilities discovered by blockchain security firm CertiK. These vulnerabilities, detailed in four security advisories on August 14, were all addressed in version 26.7.1, an urgent security update initially released on July 27. The intentional delay between the patch release and the public disclosure of details gave node operators a crucial window to update. JiaLiang Chang, CertiK's Director of Security Engineering, explained this "patch first, details later" model provides defenders a time advantage, allowing them to identify affected systems, test the update, and coordinate deployments—particularly important for institutional or permissioned blockchain networks requiring formal change management. The vulnerabilities, found through CertiK's "Chain Scan" attack methodology, involved issues in block announcement handling, consensus proposal buffering, WebSocket subscription limits, and JSON-RPC filter creation. If exploited, they could have allowed an attacker to exhaust a node's memory or thread resources, compromising its availability and the consensus process. Chang highlighted that while the open-source ecosystem is moving toward more formalized security testing (like differential fuzzing and bug bounty programs), coverage remains uneven. Testing often focuses more on protocol compliance than on continuous resource exhaustion, race conditions, or deployment-specific failures. He emphasized that third-party research remains vital for uncovering attack vectors beyond routine development, advocating for a mature, cumulative security model combining continuous integration, multi-node attack testing, independent audits, and regression testing for each confirmed vulnerability.

cryptonews.ru08/24 08:36

Besu Patches Vulnerabilities in 5 Components: What Node Operators Need to Know

cryptonews.ru08/24 08:36

Zcash Developers Recommend Upgrading Nodes to Ironwood Fork

The Zcash Foundation has released Zebra 6.0.0 and recommends all node operators upgrade to the Ironwood fork. This update introduces a new shielded pool and version 6 transaction format. The change was prompted by a vulnerability discovered in the old Orchard pool that could have allowed an attacker to create counterfeit $ZEC undetected. Developers patched the vulnerability in June, finding no evidence of exploitation, though Zcash's privacy architecture prevents absolute certainty. Ironwood utilizes the Orchard action structure and Halo2 proof system. It adds a separate note commitment tree, a nullifier set, a network value pool, and network history data. After activation, nodes can track the new pool independently from Orchard. Zebra also updates node commands for operators to verify pool and commitment tree states. This upgrade is critical, as older software will not follow the correct chain post-activation. Ironwood's key protection mechanism is a "turnstile" between the Orchard and new pools. Once activated, Orchard will stop accepting new outputs and internal transfers. Funds can be withdrawn, but an accounting rule prevents withdrawing more $ZEC from Orchard than was legitimately deposited. This design allows public auditing of the circulating supply without revealing private balances or transaction details, with any excess capital becoming locked inside Orchard. Zcash had scheduled this hardfork for July 28 after developers confirmed the patched bug raised inflation concerns.

cryptonews.ru07/27 16:36

Zcash Developers Recommend Upgrading Nodes to Ironwood Fork

cryptonews.ru07/27 16:36

活动图片