0x16dd6be516dd…16dd6be2

ConfirmedSecurity612 vB93 sat/vB3 min decode

Ledger Denies Hack Claims, Says Ethereum App Flaw Was Patched

Ledger denies it was hacked after OneKey reproduced a patched transaction-replacement flaw in Ethereum app 1.22.1, fixed in 1.22.2 on Aug. 13.

No, Ledger Wasn’t Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says - Yahoo Tech
WitnessNo, Ledger Wasn’t Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says - Yahoo TechAI-generated

Outputs

  1. OneKey's Anzen team reproduced the flaw in Ledger Ethereum app version 1.22.1.

  2. Ledger patched the vulnerability in Ethereum app 1.22.2, released August 13.

  3. The root cause was fixed in Secure SDK 26.6.1 on August 21; Ledger's bulletin came August 27.

  4. Ledger says it found no evidence of in-the-wild exploitation of the bug.

  5. Exploitation required prior host compromise via malware, a compromised wallet app or a hostile website.

Ledger says it was not hacked, after rival hardware wallet maker OneKey reproduced a transaction-replacement vulnerability in an outdated version of Ledger's Ethereum app. The French wallet developer confirmed the flaw existed but stated it was identified and patched in Ethereum app version 1.22.2, released August 13 — before OneKey published its claims.

On Thursday, OneKey founder and CEO Yishi Wang wrote on X that the company's Anzen security team recreated the attack against Ethereum app version 1.22.1 in a laboratory setting. Wang described the mechanics as a timing problem in the signing flow.

"The bug is a race condition between the transaction display logic and the underlying transaction buffer," Wang wrote. "An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one."

In practice, an attacker who had already compromised the software communicating with a vulnerable Ledger device could display a legitimate Ethereum transaction, then swap its details before signing — redirecting funds without the change appearing on the device screen.

What does Ledger's response actually say?

Ledger Chief Technology Officer Charles Guillemet rejected OneKey's framing outright, arguing that reproducing an already-fixed bug does not constitute hacking the company.

"What this thread describes is a vulnerability in an outdated version of the Ethereum app," Guillemet responded on X. "It was identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post."

In a security bulletin published Thursday, Ledger said the flaw could cause an affected app to display one transaction while signing another. Exploitation required a precondition: the attacker first needed to control communications between the device and its host through malware, a compromised wallet application or a hostile website. Ledger said it found no evidence of exploitation outside a laboratory.

"No user was hacked. No exploitation in the wild," Guillemet wrote. "Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding."

How was the vulnerability remediated?

Ledger's remediation proceeded in three stages:

  • August 13: safeguards added in Ethereum app version 1.22.2.
  • August 21: the underlying issue addressed in Secure SDK version 26.6.1, with Ledger's apps rebuilt on the corrected software.
  • August 27: publication of the full security bulletin.

Ledger recommends users install Ethereum app version 1.22.3 or later, which also fixes a separate transaction-display vulnerability. The company advised customers to update firmware and apps through Ledger Wallet and to verify the version number shown on the device, noting that apps and firmware update separately.

When asked about OneKey's claims, Ledger pointed to Ledger Donjon, its internal security research team. In a separate X post, Donjon argued the episode demonstrates why hardware wallets must support over-the-air updates.

"All software has bugs. Hardware wallets are no exception," the team wrote. "That's why updateability is a core part of Ledger's security architecture: when a vulnerability is found, whether by our own Donjon team or by external researchers, we can patch every device in the field. A wallet that can't be updated can't be fixed."

The dispute lands weeks after attackers stole more than $130 million in Bitcoin from users of Coldcard air-gapped wallets — an incident Guillemet called a warning for the hardware wallet industry. He added that the Donjon lab exists "to try to break our products before anyone else can." With the patched app and SDK now deployed across the installed base, the operational question for users is straightforward: verifying they run Ethereum app 1.22.3 or later on updated firmware.

via x.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles