CVE-2020-6861
Homebrew vulnerability analysis and mitigation

Overview

A flawed protocol design was discovered in the Ledger Monero app versions before 1.5.1 for Ledger Nano and Ledger S devices. The vulnerability (CVE-2020-6861) was identified in January 2020 and allowed a local attacker to extract the master spending key by sending crafted messages to the Monero app when selected on a PIN-entered Ledger connected to a host PC (Ledger Bulletin, Deadcode Blog).

Technical details

The vulnerability stemmed from multiple protocol weaknesses in the transaction signing process. The attack exploited type confusion between scalars and points in the protocol, where encrypted values could be used interchangeably. The attack utilized a decryption oracle through the mlsag_sign function and leveraged the reuse of the alpha parameter. The vulnerability allowed attackers to extract the master spending key through a series of carefully crafted API calls, requiring only 5 API calls in the basic version of the attack (Deadcode Blog).

Impact

The vulnerability required no user confirmation and was unobservable by normal users - no error messages were shown and the display did not change during the attack. The exploitation was possible from the initial protocol deployment date, meaning user spend keys could have been silently exfiltrated without users' knowledge. There was no way to determine if this attack was executed in the wild, making all existing wallets potentially compromised (Deadcode Blog).

Exploitability

The vulnerability could be exploited by a malicious Monero client through a connected Ledger device with an entered PIN and selected Monero app. The attack required no user interaction or confirmation and was completely invisible to users. Two different attack methods were discovered, with the second method being more sophisticated and able to bypass simple countermeasures (Ledger Bulletin).

Mitigation and workarounds

The vulnerability was fixed in Monero app version 1.5.1 released in March 2020. The fixes included removing the monero_apdu_secret_sub function, implementing strict state machine checks, adding type tags to HMAC computation to prevent type confusion, and improving user interaction by requiring confirmation for transaction starts. Users were advised to update to the new version and use different derivation paths not affected by this vulnerability (Ledger Bulletin).

Community reactions

Ledger responded promptly to the vulnerability report and worked collaboratively with the security researcher. The researcher was awarded under the bug bounty program. The cooperation between Ledger and the researcher was described as nice and seamless (Deadcode Blog).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73939HIGH8.6
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73937HIGH8.2
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73938HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73936HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73935HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management