In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @metamask/eth-ledger-bridge-keyring
to version 0.2.2 or higher.
@metamask/eth-ledger-bridge-keyring is an implementation of MetaMask's Keyring interface, that uses a Ledger hardware wallet for all cryptographic operations.
Affected versions of this package are vulnerable to Improper Authentication. It affects users who are using this library to sign with a BIP44
account other than the first account. If a user is signing with the first account (i.e. the account at index 0), or with the legacy MEW/MyCrypto
HD path, they are not affected.