BlockBeats report: On August 28, the OneKey security team, OneKey Anzen, reproduced the Ledger vulnerability disclosed by TestMachine and found that Ledger’s Ethereum app version 1.22.1 contains a transaction replacement vulnerability. Even though the hardware screen still displays transaction A, which the user is reviewing, the device may sign transaction B, which the user never saw.
OneKey Anzen stated that the issue is fundamentally a race condition between the transaction display logic and the underlying buffer; the attack requires the host side to already be compromised by a malicious dApp or intermediary software.
On August 22, TestMachine identified a security vulnerability in the well-known cryptocurrency wallet Ledger. The next day, Ledger’s CTO responded that the fix had been deployed approximately two weeks prior and urged users to simply update their app, advising the community to “not create panic.” However, public records show that the official tag for version 1.22.2 on Ledger’s GitHub did not appear until August 24.
As of the time of this report, Ledger has updated its official website with the latest information, stating that the issue has been resolved through application-level checksums and SDK-level fixes. Ledger Secure SDK v26.6.1 was released on August 21, and affected applications have been rebuilt and republished. Users must update their applications via Ledger Live; updating the device firmware alone is insufficient to complete the fix. However, Ledger noted that there is currently no evidence that this vulnerability has been exploited in practice.

