ChainCatcher report: OneKey’s security team successfully replicated an exploit targeting the older version of the Ledger Ethereum app in a laboratory environment. Wang Yishi, founder and CEO of OneKey, stated that they executed a “transaction replacement attack” on Ledger Ethereum app version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite a transaction awaiting signature while the user reviews a legitimate transaction. Ledger responded that exploiting this vulnerability requires control over communication between the device and host, such as through malware, compromised wallet software, or malicious websites. Ledger added application-layer protections in the Ethereum app version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users have been compromised, and this was purely a laboratory-based vulnerability replication. This security test followed the Coldcard vulnerability incident, during which certain Coldcard wallets were found to have security risks in mnemonic generation due to a firmware flaw. However, Ledger stated its devices were unaffected, as recovery phrases are generated by an authenticated random source embedded in the device’s secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic generation and instead affects how transactions are processed during the signing process.
OneKey Reproduces Transaction Replacement Attack on Old Ledger Ethereum App
ChaincatcherShare
OneKey’s security team successfully reproduced a "transaction replacement attack" targeting Ledger’s Ethereum app version 1.22.1 in a lab environment. The exploit enables an attacker to overwrite pending transactions while users review legitimate ones. Ledger clarified that the vulnerability requires control over device-host communication, such as through malware or malicious websites. The company patched the issue in Ethereum app version 1.22.2 and Secure SDK 26.6.1. No users were affected, as the test was conducted in a controlled environment. This incident follows the Coldcard firmware issue, though Ledger emphasized that its devices were not compromised. OneKey’s test reveals a flaw in Ethereum transaction handling during signing, unrelated to recovery phrase generation. This development in the Ethereum ecosystem underscores ongoing security efforts within the Ethereum community.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.