Ledger has pushed back on claims that its hardware wallet was hacked after OneKey researchers demonstrated a transaction-replacement flaw on an older version of the company’s Ethereum app. According to Ledger, the issue shown by OneKey’s Anzen security team affected Ethereum app 1.22.1 and had already been fixed before the demonstration was made public.
OneKey founder Yishi Wang said the attack was completed in a lab setting. Ledger responded that the test did not amount to a breach of the Ledger platform itself, arguing that researchers reproduced a known flaw in an outdated application rather than compromising the device operating system, firmware, or private keys.
What the flaw allowed
The bug concerned communication between a Ledger device and the host it was connected to. Under the affected setup, an application could accept a second APDU command while the user was still reviewing an earlier operation on the device.
That created a situation where signing parameters could be overwritten without the information shown on screen being refreshed. In practice, this meant a user could be shown one transaction while approving another. Ledger said the flaw did not expose seed phrases or private keys.
Conditions needed for exploitation
Ledger said the issue was not something that could be triggered remotely against an unplugged device. To exploit it, an attacker would need control over the connection between the wallet and its host, such as through malware, a compromised wallet application, or a hostile webpage with WebHID or WebUSB access.
The user would still need to approve the transaction while malicious software altered the signing context in the background. Ledger characterized the weakness as application-specific and tied to the Secure SDK’s input and output handling rather than to the wallet’s core operating system or firmware.
Ledger’s response and patch timeline
Ledger CTO Charles Guillemet disputed descriptions of the event as a “hack of Ledger,” calling OneKey’s result a laboratory reproduction against an older software version. Ledger said Ethereum app 1.22.2 added state checks to address the issue, and that broader protections were later included in Secure SDK 26.6.1.
The company’s timeline also includes rebuilt applications based on the corrected SDK. Ledger now recommends using Ethereum app 1.22.3 or later, which it says contains the updated safeguards.
What users and developers should do next
Ledger said users should update device applications through Ledger Live and confirm the installed Ethereum app version, noting that a firmware update alone does not replace affected apps. The company’s current recommendation is to run Ethereum app 1.22.3 or newer.
For third-party developers, Ledger said applications should be rebuilt with Secure SDK 26.6.1 or later. The company added that it has found no evidence of this flaw being exploited in the wild and no known losses linked to the issue.
Source: crypto.news