
Ledger says the viral “hack” was already patched, but two real bugs still needed fixing
The company disputed OneKey’s framing while separately closing two Ethereum signing vulnerabilities.
Follow crypto hack news, exploits, bridge attacks, protocol breaches, and security lessons from major incidents across Web3.

Core Lightning is urging node operators to upgrade or go offline as multiple vulnerabilities remain under embargo.

Repository history places the official protection in 0.21.0, leaving earlier standard releases exposed unless separately patched.

Trail of Bits says the flaw put token supply and about $500,000 of HASH escrow at risk, but no exploitation was confirmed.

Socket confirmed 40 malicious IDs, and exposed crypto wallet secrets still require migration after the add-ons are removed.

Withdrawals remain open, but Term Finance has not confirmed the loss or promised to cover any user shortfall.

Version 1.22.2 adds two signing-state safeguards to Ethereum, but public physical validation of the alleged substitution path is limited to Flex.



