Huo Xing Cai Jing reports that OneKey’s security team successfully replicated an exploit targeting the older version of the Ledger Ethereum app in a laboratory environment. Wang Yishi, founder and CEO of OneKey, stated that they executed a “transaction replacement attack” on Ledger Ethereum app version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite transactions awaiting signature while users review legitimate transactions. Ledger responded that exploiting this vulnerability requires control over communication between the device and host, such as through malware, compromised wallet software, or malicious websites. Ledger added application-layer protections in the Ethereum app version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users have been compromised by this exploit; the incident was purely a laboratory reproduction. This security test followed the Coldcard vulnerability incident, during which certain Coldcard wallets were found to have security risks in mnemonic generation due to a firmware flaw. However, Ledger stated its devices were unaffected, as recovery phrases are generated by an authenticated random source embedded in the device’s secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic generation and instead affects how transactions are processed during the signing process.
OneKey Reproduces Transaction Replacement Attack on Ledger Ethereum App Version 1.22.1
MarsBitShare
Ethereum news: OneKey’s security team confirmed a transaction replacement attack on Ledger’s Ethereum app version 1.22.1 during a lab test. The vulnerability, previously patched, allowed attackers to replace pending transactions during user review. Ledger stated that exploitation requires control over device-host communication, such as through malware. On-chain news: App-layer protection was added in version 1.22.2 on August 13, with a more comprehensive fix delivered in Secure SDK 26.6.1 on August 21. Ledger confirmed no users were affected, as the test was conducted in a lab environment. The test followed a Coldcard firmware incident, but Ledger emphasized its devices were not impacted.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.