4242 < link rel ="icon " href ="/favicon.ico " sizes ="any ">
4343 < link rel ="icon " href ="/favicon.svg " type ="image/svg+xml ">
4444 < link rel ="apple-touch-icon " href ="/apple-touch-icon.png ">
45- < link rel ="stylesheet " href ="/assets/css/style.css?v=1788803857 ">
45+ < link rel ="stylesheet " href ="/assets/css/style.css?v=1788804508 ">
4646</ head >
4747
4848 < body class ="layout-post section-blog ">
@@ -105,18 +105,18 @@ <h1>Signature overflow attacks on Ledger</h1>
105105
106106< nav class ="post-toc " aria-label ="Contents "> < p class ="post-toc-title "> Contents</ p >
107107< ul >
108- < li > < a href ="#0x00---the-threat-model "> 0x00 - The Threat Model</ a > </ li >
109- < li > < a href ="#0x01---the-parser-bug "> 0x01 - The Parser Bug</ a > </ li >
110- < li > < a href ="#0x02---signed-metadata "> 0x02 - Signed Metadata</ a > </ li >
111- < li > < a href ="#0x03---safe "> 0x03 - Safe</ a > </ li >
112- < li > < a href ="#0x04---aave "> 0x04 - Aave</ a > </ li >
113- < li > < a href ="#0x05---morpho "> 0x05 - Morpho</ a > </ li >
114- < li > < a href ="#0x06---making-257-calls-fit "> 0x06 - Making 257 Calls Fit</ a > </ li >
115- < li > < a href ="#0x07---research-evidence "> 0x07 - Research Evidence</ a > </ li >
116- < li > < a href ="#0x08---fix-and-release "> 0x08 - Fix and Release</ a > </ li >
117- < li > < a href ="#conclusion-one-thing-well "> 0x09 - Conclusion: One Thing Well</ a > </ li >
118- < li > < a href ="#appendix-disclosure-record "> 0x0A - Appendix: Disclosure Record</ a > </ li >
119- </ ul > </ nav > < h2 id ="0x00---the-threat-model "> 0x00 - The Threat Model</ h2 >
108+ < li > < a href ="#0x00---the-threat-model "> 00 - The Threat Model</ a > </ li >
109+ < li > < a href ="#0x01---the-parser-bug "> 01 - The Parser Bug</ a > </ li >
110+ < li > < a href ="#0x02---signed-metadata "> 02 - Signed Metadata</ a > </ li >
111+ < li > < a href ="#0x03---safe "> 03 - Safe</ a > </ li >
112+ < li > < a href ="#0x04---aave "> 04 - Aave</ a > </ li >
113+ < li > < a href ="#0x05---morpho "> 05 - Morpho</ a > </ li >
114+ < li > < a href ="#0x06---making-257-calls-fit "> 06 - Making 257 Calls Fit</ a > </ li >
115+ < li > < a href ="#0x07---research-evidence "> 07 - Research Evidence</ a > </ li >
116+ < li > < a href ="#0x08---fix-and-release "> 08 - Fix and Release</ a > </ li >
117+ < li > < a href ="#conclusion-one-thing-well "> 09 - Conclusion: One Thing Well</ a > </ li >
118+ < li > < a href ="#appendix-disclosure-record "> 10 - Appendix: Disclosure Record</ a > </ li >
119+ </ ul > </ nav > < h2 id ="0x00---the-threat-model "> 00 - The Threat Model</ h2 >
120120
121121< p > Ledger’s security premise is sound: the computer and transaction interface may
122122be compromised. Its
@@ -153,7 +153,7 @@ <h1>Signature overflow attacks on Ledger</h1>
153153Clear Signing produces a human-readable description that omits part of the
154154signed authorization.</ p >
155155
156- < h2 id ="0x01---the-parser-bug "> 0x01 - The Parser Bug</ h2 >
156+ < h2 id ="0x01---the-parser-bug "> 01 - The Parser Bug</ h2 >
157157
158158< p > The vulnerability was in the shared array machinery of Ledger’s Ethereum
159159Generic Transaction Parser. The parser calculated an attacker-controlled array
@@ -196,7 +196,7 @@ <h2 id="0x01---the-parser-bug">0x01 - The Parser Bug</h2>
196196the device’s constraints. The demonstrated Safe payload uses < code class ="language-plaintext highlighter-rouge "> q = 1</ code > and
197197< code class ="language-plaintext highlighter-rouge "> k = 1</ code > : the screen reviews one call while the signature authorizes 257.</ p >
198198
199- < h2 id ="0x02---signed-metadata "> 0x02 - Signed Metadata</ h2 >
199+ < h2 id ="0x02---signed-metadata "> 02 - Signed Metadata</ h2 >
200200
201201< p > Clear Signing does not interpret every contract call generically. A transaction
202202enters this parser path only when a host-side Context Module supplies matching,
@@ -300,7 +300,7 @@ <h2 id="0x02---signed-metadata">0x02 - Signed Metadata</h2>
300300impact especially clear. Aave and Morpho extend the result beyond Safe and
301301EIP-712 authorization.</ p >
302302
303- < h2 id ="0x03---safe "> 0x03 - Safe</ h2 >
303+ < h2 id ="0x03---safe "> 03 - Safe</ h2 >
304304
305305< p > Safe’s < code class ="language-plaintext highlighter-rouge "> BatchExecutor</ code > provided a path from parser failure to treasury impact.
306306Its < code class ="language-plaintext highlighter-rouge "> batchExecute(Call[])</ code > entry point accepts an array whose elements contain a
@@ -388,7 +388,7 @@ <h2 id="0x03---safe">0x03 - Safe</h2>
388388< p > That run proves a signature produced after an incomplete device review was
389389blockchain-usable.</ p >
390390
391- < h2 id ="0x04---aave "> 0x04 - Aave</ h2 >
391+ < h2 id ="0x04---aave "> 04 - Aave</ h2 >
392392
393393< p > Aave V3’s archived
394394< a href ="/assets/images/blog/clear-signing-considered-harmful/metadata/aave-v3-multicall-ledger-signed-context.json "> < code class ="language-plaintext highlighter-rouge "> multicall(bytes[])</ code > context</ a >
@@ -411,7 +411,7 @@ <h2 id="0x04---aave">0x04 - Aave</h2>
411411< p > < em > The affected app reviewed the final supply entry. The signed multicall also
412412contained the preceding withdrawal.</ em > </ p >
413413
414- < h2 id ="0x05---morpho "> 0x05 - Morpho</ h2 >
414+ < h2 id ="0x05---morpho "> 05 - Morpho</ h2 >
415415
416416< p > Morpho’s archived Bundler3
417417< a href ="/assets/images/blog/clear-signing-considered-harmful/metadata/morpho-bundler3-multicall-ledger-signed-context.json "> < code class ="language-plaintext highlighter-rouge "> multicall</ code > context</ a >
@@ -439,7 +439,7 @@ <h2 id="0x05---morpho">0x05 - Morpho</h2>
439439shapes: the screen reviewed a suffix while the signature authorized the whole
440440array.</ p >
441441
442- < h2 id ="0x06---making-257-calls-fit "> 0x06 - Making 257 Calls Fit</ h2 >
442+ < h2 id ="0x06---making-257-calls-fit "> 06 - Making 257 Calls Fit</ h2 >
443443
444444< p > Practical exploitation also had to satisfy the device’s memory constraints.</ p >
445445
@@ -479,7 +479,7 @@ <h2 id="0x06---making-257-calls-fit">0x06 - Making 257 Calls Fit</h2>
479479signature remains cryptographically correct. The trusted interpretation omits
480480signed actions.</ p >
481481
482- < h2 id ="0x07---research-evidence "> 0x07 - Research Evidence</ h2 >
482+ < h2 id ="0x07---research-evidence "> 07 - Research Evidence</ h2 >
483483
484484< p > The completed research evidence includes:</ p >
485485
@@ -556,7 +556,7 @@ <h3 id="hardware-proof-of-concept">Hardware Proof of Concept</h3>
556556and a disposable seed. The fixed Ethereum app rejects the malformed array. The
557557page does not offer an archived-signature fallback and never broadcasts.</ p >
558558
559- < h2 id ="0x08---fix-and-release "> 0x08 - Fix and Release</ h2 >
559+ < h2 id ="0x08---fix-and-release "> 08 - Fix and Release</ h2 >
560560
561561< p > < strong > Source correction: May 5. Installable release: August 25.</ strong > </ p >
562562
@@ -616,7 +616,7 @@ <h2 id="0x08---fix-and-release">0x08 - Fix and Release</h2>
616616< p > We are publishing with fixed Ethereum app < code class ="language-plaintext highlighter-rouge "> 1.22.3</ code > available through Ledger’s
617617normal application catalog.</ p >
618618
619- < h2 id ="conclusion-one-thing-well "> 0x09 - Conclusion: One Thing Well</ h2 >
619+ < h2 id ="conclusion-one-thing-well "> 09 - Conclusion: One Thing Well</ h2 >
620620
621621< p > Version < code class ="language-plaintext highlighter-rouge "> 1.22.3</ code > removes this truncation. The harder question remains: what
622622other bugs could emerge from the same firmware complexity?</ p >
@@ -652,7 +652,7 @@ <h2 id="conclusion-one-thing-well">0x09 - Conclusion: One Thing Well</h2>
652652human-readable views could run across independent, replaceable systems that
653653bind their conclusions to the same hash.</ p >
654654
655- < h2 id ="appendix-disclosure-record "> 0x0A - Appendix: Disclosure Record</ h2 >
655+ < h2 id ="appendix-disclosure-record "> 10 - Appendix: Disclosure Record</ h2 >
656656
657657< p > Dates use < code class ="language-plaintext highlighter-rouge "> YYYY-MM-DD</ code > . Times in the underlying correspondence are retained in
658658< code class ="language-plaintext highlighter-rouge "> America/Argentina/Cordoba</ code > (< code class ="language-plaintext highlighter-rouge "> ART</ code > , UTC-3). The table records confirmed email
@@ -774,6 +774,6 @@ <h2 class="section-title" id="connected-title">Stay <span>Connected</span>
774774 </ div >
775775</ footer >
776776
777- < script src ="/assets/js/site.js?v=1788803857 " defer > </ script >
777+ < script src ="/assets/js/site.js?v=1788804508 " defer > </ script >
778778 </ body >
779779</ html >
0 commit comments