In brief

  • OneKey reproduced a transaction-replacement attack against version 1.22.1 of Ledger’s Ethereum app.
  • Ledger says it fixed the vulnerability in version 1.22.2 before OneKey published its test and has seen no evidence of attacks against users.
  • Ledger recommends installing Ethereum app version 1.22.3 or later and checking the app version on the device.

Cryptocurrency wallet developer Ledger rejects claims that it had been hacked after researchers at rival wallet maker OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger’s Ethereum app.

On Thursday, Yishi Wang, founder and CEO of OneKey, said on X that the company’s Anzen security team recreated the attack against Ethereum app version 1.22.1 in a lab.

Myriad: Ethereum next price move? Click to make your prediction.
Myriad: Ethereum next price move? Click to make your prediction.

“The bug is a race condition between the transaction display logic and the underlying transaction buffer,” Wang wrote. “An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.”

That would mean a hacker who had compromised the software communicating with a vulnerable Ledger app could show the user a legitimate Ethereum transaction, then replace its details before signing, redirecting funds to the hacker’s wallet without the change appearing on the device.

Ledger Chief Technology Officer Charles Guillemet rejected OneKey’s characterization, saying that reproducing an already-patched bug does not amount to “hacking Ledger.”

“What this thread describes is a vulnerability in an outdated version of the Ethereum app,” he responded on X. “It was identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post.”

In a security bulletin published on Thursday, Ledger said the flaw could cause an affected app to display one transaction while signing another. An attacker would first need to control communications between the device and its host through malware, a compromised wallet app or a hostile website.

Ledger said it found no evidence that anyone exploited the vulnerability outside a laboratory.

“No user was hacked. No exploitation in the wild,” Guillemet wrote. “Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding.”

Ledger added safeguards in Ethereum app version 1.22.2 on Aug. 13, then addressed the underlying issue in Secure SDK version 26.6.1 on Aug. 21 and rebuilt its apps with the corrected software. The company recommends version 1.22.3 or later, which also fixes a separate transaction-display vulnerability. Ledger published its bulletin on Aug. 27.

When asked about Onekey’s claims, Ledger pointed Decrypt to Ledger Donjon, the company’s internal security research team, which said in a separate X post that the episode showed why hardware wallets need to support software updates.

“All software has bugs. Hardware wallets are no exception,” the team wrote. “That’s why updateability is a core part of Ledger’s security architecture: when a vulnerability is found, whether by our own Donjon team or by external researchers, we can patch every device in the field. A wallet that can’t be updated can’t be fixed.”

Myriad: Solana next price move? Click to make your prediction.
Myriad: Solana's next price move? Click to make your prediction.

Ledger advised customers to install the latest firmware and apps through Ledger Wallet, update the Ethereum app to version 1.22.3 or later, and verify the version shown on the device. Apps and firmware update separately.

Earlier this month, after attackers stole more than $130 million in Bitcoin from users of Coldcard air-gapped wallets, Guillemet told Decrypt that the incident was a warning for the hardware wallet industry.

“We also don't just rely on our own word for it,” he said. “Our Donjon research lab exists to try to break our products before anyone else can.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.