- Researchers at OneKey reproduced a transaction-replacement attack against Ledger’s Ethereum app version 1.22.1
- Ledger states it patched the vulnerability in version 1.22.2 before OneKey’s disclosure and found no evidence of real-world exploitation
- Ledger recommends users update to Ethereum app version 1.22.3 or later to ensure protection
Ledger has rejected claims that it was hacked after rival wallet maker OneKey reproduced a transaction-replacement vulnerability targeting an outdated version of its Ethereum app. On Thursday, OneKey founder and CEO Yishi Wang said on X that the company’s security team recreated the attack against version 1.22.1 in a lab.
“The bug is a race condition between the transaction display logic and the underlying transaction buffer,” Wang wrote. “An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.”
The exploit would allow a Hacker who compromised the software communicating with a vulnerable Ledger app to display a legitimate transaction, then swap its details before signing. Funds would redirect to the attacker’s wallet without the change appearing on the device.
Ledger Chief Technology Officer Charles Guillemet responded on X, rejecting OneKey‘s characterization. “What this thread describes is a vulnerability in an outdated version of the Ethereum app,” he said, noting it was identified and fixed in version 1.22.2, released August 13.
In a security bulletin, Ledger said the flaw could cause an affected app to display one transaction while signing another. An attacker would first need to control communications between the device and its host through Malware, a compromised wallet app, or a hostile website.
Ledger found no evidence that anyone exploited the vulnerability outside a laboratory. “No user was hacked. No exploitation in the wild,” Guillemet wrote.
Ledger added safeguards in Ethereum app version 1.22.2 on August 13, then addressed the underlying issue in Secure SDK version 26.6.1 on August 21. The company recommends version 1.22.3 or later, which also fixes a separate transaction-display vulnerability.
Ledger‘s internal security team, Ledger Donjon, said on X that the episode showed why hardware wallets need to support software updates. “All software has bugs. Hardware wallets are no exception,” the team wrote, noting that updateability is a core part of Ledger‘s security architecture.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
