
Cloud Vulnerability DB
A community-led vulnerabilities database
A flawed protocol design was discovered in the Ledger Monero app versions before 1.5.1 for Ledger Nano and Ledger S devices. The vulnerability (CVE-2020-6861) was identified in January 2020 and allowed a local attacker to extract the master spending key by sending crafted messages to the Monero app when selected on a PIN-entered Ledger connected to a host PC (Ledger Bulletin, Deadcode Blog).
The vulnerability stemmed from multiple protocol weaknesses in the transaction signing process. The attack exploited type confusion between scalars and points in the protocol, where encrypted values could be used interchangeably. The attack utilized a decryption oracle through the mlsag_sign function and leveraged the reuse of the alpha parameter. The vulnerability allowed attackers to extract the master spending key through a series of carefully crafted API calls, requiring only 5 API calls in the basic version of the attack (Deadcode Blog).
The vulnerability required no user confirmation and was unobservable by normal users - no error messages were shown and the display did not change during the attack. The exploitation was possible from the initial protocol deployment date, meaning user spend keys could have been silently exfiltrated without users' knowledge. There was no way to determine if this attack was executed in the wild, making all existing wallets potentially compromised (Deadcode Blog).
The vulnerability could be exploited by a malicious Monero client through a connected Ledger device with an entered PIN and selected Monero app. The attack required no user interaction or confirmation and was completely invisible to users. Two different attack methods were discovered, with the second method being more sophisticated and able to bypass simple countermeasures (Ledger Bulletin).
The vulnerability was fixed in Monero app version 1.5.1 released in March 2020. The fixes included removing the monero_apdu_secret_sub function, implementing strict state machine checks, adding type tags to HMAC computation to prevent type confusion, and improving user interaction by requiring confirmation for transaction starts. Users were advised to update to the new version and use different derivation paths not affected by this vulnerability (Ledger Bulletin).
Ledger responded promptly to the vulnerability report and worked collaboratively with the security researcher. The researcher was awarded under the bug bounty program. The cooperation between Ledger and the researcher was described as nice and seamless (Deadcode Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."