OneKey Anzen Reproduces Ledger Vulnerability; Users May Encounter Mismatched Transaction Approval

iconKuCoinFlash
Share
AI summary iconSummary
OneKey Anzen confirmed a vulnerability report on August 28, reproducing a flaw in Ledger’s Ethereum app version 1.22.1 that allows a signed transaction to differ from the one displayed on the device. Ledger’s CTO stated that a fix was deployed two weeks ago, with version 1.22.2 tagged on GitHub on August 24. Ledger has updated its app and SDK, urging users to update via Ledger Live. The incident underscores ongoing concerns regarding hardware wallet security.

BlockBeats report: On August 28, the OneKey security team, OneKey Anzen, reproduced the Ledger vulnerability disclosed by TestMachine and found that Ledger’s Ethereum app version 1.22.1 contains a transaction replacement vulnerability. Even though the hardware screen still displays transaction A, which the user is reviewing, the device may sign transaction B, which the user never saw.


OneKey Anzen stated that the issue is fundamentally a race condition between the transaction display logic and the underlying buffer; the attack requires the host side to already be compromised by a malicious dApp or intermediary software.


On August 22, TestMachine identified a security vulnerability in the well-known cryptocurrency wallet Ledger. The next day, Ledger’s CTO responded that the fix had been deployed approximately two weeks prior and urged users to simply update their app, advising the community to “not create panic.” However, public records show that the official tag for version 1.22.2 on Ledger’s GitHub did not appear until August 24.


As of the time of this report, Ledger has updated its official website with the latest information, stating that the issue has been resolved through application-level checksums and SDK-level fixes. Ledger Secure SDK v26.6.1 was released on August 21, and affected applications have been rebuilt and republished. Users must update their applications via Ledger Live; updating the device firmware alone is insufficient to complete the fix. However, Ledger noted that there is currently no evidence that this vulnerability has been exploited in practice.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.