Bitcoin Forum

Bitcoin => Hardware wallets => Topic started by: usmanov123 on February 09, 2018, 02:27:10 PM



Title: Ledger Nano S. Question about sending BTC
Post by: usmanov123 on February 09, 2018, 02:27:10 PM
Hi. When Im sending BTC i have 2 confirmations on the devices display. 1st - receive address and the amount. And the 2nd Im concern of. There are different address and another amount. After reading about the attack i havent send anything.


Title: Re: Ledger Nano S. Question about sending BTC
Post by: Lucius on February 09, 2018, 02:54:47 PM
Hi. When Im sending BTC i have 2 confirmations on the devices display. 1st - receive address and the amount. And the 2nd Im concern of. There are different address and another amount. After reading about the attack i havent send anything.

This is just your device ask you to confirm change address,it is normal in HD wallets to have change address.So when you send 0.01 BTC and you have in total 0.02 BTC,0.01 + fee will be send to address you pick,and rest will be send (free) on change address.I notice this few days ago first time in Electrum 3.0.5 in combination with Ledger Nano S.

From Ledger support is explained that sometimes as they say "minor bug" can cause such behavior on device.It should be safe,but since latest reports how easy is for malware to create receiving address in Chrome app,this is also represents a security problem.

https://support.ledgerwallet.com/hc/en-us/articles/115005469005-What-if-two-Outputs-are-displayed-Transfer-to-a-Change-address


Title: Re: Ledger Nano S. Question about sending BTC
Post by: bob123 on February 09, 2018, 05:21:43 PM
Hi. When Im sending BTC i have 2 confirmations on the devices display. 1st - receive address and the amount. And the 2nd Im concern of. There are different address and another amount.

As already mentionoed this is your change address.

This was a small 'bug' in an older version of the ledger nano s.
I would advise you to update your software.

Current versions:
Code:
Bitcoin Chrome: 1.10.1
Bitcoin app (on your nano s): 1.1.18
Firmware: 1.3.1



After reading about the attack i havent send anything.

The new "attack" is replacing your recieving address in the GUI of your application.
Ledger already has a workaround ready where you have to confirm your recieving address ony our nano S.

Note: The attack vector covers the GUI of your wallet. Not the wallet / the nano s itself.
Everything you confirm on your nano s can be considered as verified and safe.