BackLedger Rejects Hacking Claims Following OneKey Vulnerability Report
Ledger Rejects Hacking Claims Following OneKey Vulnerability Report
Tech
Decrypt5 hours agoTech3 min read

Ledger Rejects Hacking Claims Following OneKey Vulnerability Report

Ledger states the reported transaction-replacement vulnerability was already patched in an outdated Ethereum app version.

Quick Look

  • Ledger has denied claims of being hacked after rival OneKey demonstrated a transaction-replacement vulnerability.
  • Ledger clarified the flaw existed only in an outdated Ethereum app version and was patched prior to the public report.

AI-generated summary

Why It Matters

Ledger maintains a security architecture that allows for remote firmware and application updates. The company's internal security team, Ledger Donjon, monitors for vulnerabilities.

Font size

Cryptocurrency wallet developer Ledger rejects claims that it had been hacked after researchers at rival wallet maker OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger’s Ethereum app.

On Thursday, Yishi Wang, founder and CEO of OneKey, said on X that the company’s Anzen security team recreated the attack against Ethereum app version 1.22.1 in a lab.

“The bug is a race condition between the transaction display logic and the underlying transaction buffer,” Wang wrote. “An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.”

That would mean a hacker who had compromised the software communicating with a vulnerable Ledger app could show the user a legitimate Ethereum transaction, then replace its details before signing, redirecting funds to the hacker’s wallet without the change appearing on the device.

Ledger Chief Technology Officer Charles Guillemet rejected OneKey’s characterization, saying that reproducing an already-patched bug does not amount to “hacking Ledger.”

“What this thread describes is a vulnerability in an outdated version of the Ethereum app,” he responded on X. “It was identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post.”

In a security bulletin published on Thursday, Ledger said the flaw could cause an affected app to display one transaction while signing another. An attacker would first need to control communications between the device and its host through malware, a compromised wallet app or a hostile website.

Ledger said it found no evidence that anyone exploited the vulnerability outside a laboratory.

“No user was hacked. No exploitation in the wild,” Guillemet wrote. “Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding.”

Ledger added safeguards in Ethereum app version 1.22.2 on Aug. 13, then addressed the underlying issue in Secure SDK version 26.6.1 on Aug. 21 and rebuilt its apps with the corrected software. The company recommends version 1.22.3 or later, which also fixes a separate transaction-display vulnerability. Ledger published its bulletin on Aug. 27.

When asked about Onekey’s claims, Ledger pointed Decrypt to Ledger Donjon, the company’s internal security research team, which said in a separate X post that the episode showed why hardware wallets need to support software updates.

“All software has bugs. Hardware wallets are no exception,” the team wrote. “That’s why updateability is a core part of Ledger’s security architecture: when a vulnerability is found, whether by our own Donjon team or by external researchers, we can patch every device in the field. A wallet that can’t be updated can’t be fixed.”

Ledger advised customers to install the latest firmware and apps through Ledger Wallet, update the Ethereum app to version 1.22.3 or later, and verify the version shown on the device. Apps and firmware update separately.

Earlier this month, after attackers stole more than $130 million in Bitcoin from users of Coldcard air-gapped wallets, Guillemet told Decrypt that the incident was a warning for the hardware wallet industry.

What to Watch

AI outlook — possibilities, not facts

  • Ledger will continue to push updates to ensure users move away from vulnerable app versions.

    Very likely · Within weeks

Open Questions

  • Are there other outdated versions still in widespread use?

Related Topics

This article was originally published by Decrypt.

Related Stories

More on this topicledger