Hardware wallet provider Ledger has responded to a vulnerability in an Ethereum application. The company disclosed that the issue discussed recently was present in the older Ethereum App 1.22.1, and the fix was deployed prior to OneKey publishing its experimental reproduction results. There is currently no evidence that this vulnerability has been exploited against users in real-world scenarios.
On August 27, Wang Yishi, founder of OneKey, stated on X that his security team, Anzen, reproduced a "transaction replacement" attack in an experimental environment. According to his description, the vulnerability is related to a race condition between the transaction display logic and the underlying transaction buffer. If an attacker has compromised communication between the device and its host, they could replace the content awaiting signature while the user reviews a legitimate transaction.
A vulnerability can only be exploited if the communication link is first compromised.
In its security advisory issued today, Ledger stated that this issue could cause the device screen to display one transaction while actually signing another. However, the attack has specific prerequisites: the attacker must first compromise the communication channel between the hardware wallet and the computer or smartphone, for example, through malware, a compromised wallet application, or a malicious website.
Chief Technology Officer Charles Guillemet stated that re-running a patched vulnerability on an older version does not equate to "Ledger being hacked." He noted that the company discovered the issue through its internal security processes and had already resolved it in the Ethereum App 1.22.2 released on August 13, prior to OneKey publicly disclosing the related tests.
The repair was completed in two steps in August.
Ledger disclosed that the first step was the release of the Ethereum App 1.22.2 on August 13, adding additional protections. The second step involves fixing the underlying issue in Secure SDK 26.6.1 on August 21 and rebuilding the affected applications accordingly. The company currently recommends users upgrade to version 1.22.3 or higher, which also resolves another transaction display vulnerability.
- Affected version: Ethereum App 1.22.1
- Fix released on August 13 for 1.22.2
- Versions 1.22.3 and above are the currently recommended versions.
The company stated that it has not seen any evidence of a real attack.
Ledger stated that, as of now, there is no evidence that the vulnerability has been exploited outside the lab. Guillemet also noted that no users have been compromised by this issue, and available information indicates that the reproduction was part of laboratory testing rather than a newly discovered real-world attack.
Ledger’s security research team, Donjon, also stated on X that this incident highlights the need for hardware wallets to support software updates. The team noted that software vulnerabilities are not uncommon; what matters is whether manufacturers can quickly push patches to already-sold devices upon discovering issues.
Additional information: Earlier this month, users of the Coldcard air-gapped hardware wallet suffered a theft of over $1.3 billion in Bitcoin. At the time, Ledger executives stated that this incident served as a wake-up call for the entire hardware wallet industry.

