Ledger is urging Ethereum app users to install version 1.22.3 after two signing flaws, LSB-024 and LSB-025, remained in the prior 1.22.2 security release that had already addressed the LSB-023 transaction-replacement race condition later reproduced in a laboratory by rival OneKey. Version 1.22.3, published Aug. 25, closes an array-count clear-signing bug that could hide all but the final operation in a large batch while authorizing the full set, and a swap-path flaw that could substitute a matching token approval for an expected payment without an extra device prompt. Both additional issues required a compromised host or malicious swap provider, carried constrained impact, and showed no evidence of real-world exploitation or user losses, matching Ledger’s stance that OneKey’s demonstration targeted outdated 1.22.1 software and that no Ledger user was hacked. The company recommends installing 1.22.3 or later through Ledger Live and verifying the version on-device, noting firmware updates alone do not replace the Ethereum application.