Executive brief
The Ledger Bitcoin application, used on hardware wallets to secure cryptocurrency, contains a flaw in how it generates certain types of complex addresses. An attacker could potentially trick a user into using a malicious wallet configuration that displays an incorrect receiving address on the device's screen. If a user sends funds to this incorrect address, the money could be sent to an unintended destination, leading to a loss of funds.
Technical details
A vulnerability exists in the Ledger Bitcoin application (versions 2.1.0 and 2.1.1) due to the incorrect implementation of the 'a:' fragment within Miniscript policies. Miniscript is a language used to define complex spending conditions. By crafting a malicious miniscript policy, an attacker can cause the hardware wallet to derive and display a receiving address that does not match the intended policy. Exploitation requires physical access to the device or a compromised software wallet interface, and the user must interact with the device to approve the malicious policy. This results in an 'Incorrect Calculation' (CWE-682) where the derived address is invalid or unintended. The issue was resolved in version 2.1.2 of the Ledger Bitcoin app.
Affected products
- Ledger Bitcoin app 2.1.0, 2.1.1
Timeline
- 2023-05-11: advisory: Ledger Security Bulletin 019 published
- 2023-05-11: patched: Version 2.1.2 released to fix the issue
- 2026-05-20: disclosed: CVE-2023-7346 published to NVD