EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Ledger refutes hacker claims that OneKey reproduces a patched Ethereum vulnerability

2026-08-29 12:35:03
Bookmark

Ledger denies OneKey hacking allegations

Ledger rejected claims of hacking after rival OneKey recreated a transaction substitution attack on version 1.22.1 of the Ethereum (ETH) application. The vulnerability was fixed two weeks ago.

Core Points:

OneKey's Anzen security team successfully recreated a transaction replacement attack on version 1.22.1 of the Ledger Ethereum application in a laboratory environment. Ledger said that the underlying vulnerability was fixed in version 1.22.2 of the Ethereum application on August 13 and no signs of attacks against users were found. The company now recommends that users install version 1.22.3 or later of the Ethereum app and check the version number displayed on the device.

Ledger denies OneKey hacking allegations

OneKey founder and CEO Wang Yishi posted on the X platform on Thursday that his company's Anzen security team had fully executed the attack in a laboratory environment. He said the vulnerability was a race condition between the transaction display logic on the device and the underlying transaction buffer. Its engineers rebuilt the affected application versions themselves to recreate the full attack flow.

The Ledger team described the same problem in an announcement issued on the same day and called it a race condition. A device running the affected application may display a set of transaction details on the screen while silently generating a completely different signature.

Charles Guillemet questions characterization of attack

Charles Guillemet, chief technology officer at Ledger, said the demonstration was only a laboratory test and not an actual discovery. He believes that recreating a vulnerability that had been fixed weeks ago does not amount to hacking into the company or its users. To carry out such attacks on real users, the attacker requires that the attacker has controlled the connection between the device and the host through malware, infected crypto wallet applications, or malicious web pages. The vulnerability never exposed the seed phrase or private key stored in the security chip, but only changed the parameters of the device signature.

Ledger found no evidence that the vulnerability was used to target users in a real-world environment, nor was any stolen funds publicly associated with this vulnerability. Its Donjon research team said the incident showed why hardware wallets need to support software updates-because a wallet that cannot be repaired locally cannot be repaired at all.

Ledger Ethereum Application Patch Timeline

Ledger traces the regression vulnerability to August 2025 and said the vulnerability affects all versions of the Secure SDK released as of August 11. Application-layer protection was first launched in version 1.22.2 of the Ethereum app on August 13, about two weeks before a demonstration by rival wallet makers.

Subsequently, the company released version 26.6.1 of the Secure SDK on August 21, rebuilt its application based on this version, and issued an announcement on August 27 urging users to install version 1.22.3 or higher.

The conflict comes weeks after attackers began exploiting a firmware vulnerability dating back to March 2021 on July 30 to steal Bitcoin (BTC) from Coldcard wallets that weakened the security of seed phrases generated by these devices. Guillemet called the incident a warning to the entire industry at the time, pointing out that the security model of a hardware wallet depends entirely on the quality of its random number generation.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP