Ledger Says It Wasn't Hacked. A Rival Reproduced the Bug Anyway.
OneKey's security team recreated a transaction-replacement attack against an outdated version of Ledger's Ethereum app.

The hardware wallet maker Ledger has rejected claims that it was hacked, after researchers at the rival wallet manufacturer OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger's Ethereum app.
Yishi Wang, founder and chief executive of OneKey, said the company's Anzen security team had recreated the attack against Ethereum app version 1.22.1 in a laboratory setting.
What the flaw does
"The bug is a race condition between the transaction display logic and the underlying transaction buffer," Wang wrote. "An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one."
That description matters, because it attacks the single feature a hardware wallet exists to provide.
The entire premise of a device like this is that the screen is trustworthy. A user's computer may be fully compromised, but the wallet displays the transaction independently, and the user confirms what they can see. If the displayed transaction can be swapped for a different one in the interval between display and signature, the guarantee collapses — a user would approve a legitimate payment and authorise a transfer to an attacker's address, with no indication on the device that anything had changed.
The Ledger Flex. Hardware wallets rely on the device screen being a trustworthy display of what is actually being signed. Image: Decrypt/LedgerLedger's position
The company's response rests on two points: the vulnerability was patched before any exploit occurred, and the version OneKey tested is outdated.
Both are meaningful. A responsibly disclosed and fixed flaw is the security process working, and there is no evidence of user funds being taken. Reproducing a patched bug in a lab demonstrates that the bug was real, not that anyone is currently at risk.
The part that is genuinely uncomfortable
The complication is that hardware wallet users do not update automatically, and many deliberately avoid it.
The security culture around these devices encourages caution about firmware and app updates, on the reasonable grounds that an update is itself a moment of trust — and users who set up a wallet years ago, moved it to cold storage and left it alone are precisely the population least likely to be running current software.
A patched vulnerability protects everyone who has installed the patch. For a category of device explicitly marketed for long-term, hands-off storage, that is a smaller set of people than it would be for a phone app.
The competitive dimension
It is worth noting who published this. OneKey is a direct competitor, and vulnerability research by rivals occupies an awkward position in security disclosure.
The work appears technically sound and the flaw appears to have been real. It was also released publicly, with a video demonstration, in a way that maximises attention on a competitor's product rather than on the fix. Both things can be true, and the crypto hardware market has a long history of firms publicising each other's weaknesses.
For users the practical answer is unglamorous and unchanged: check which app version your device is running, and update it. The threat model these devices defend against assumes your computer is already hostile, and that assumption only holds if the device itself is current.
More from peatpost

Morgan Stanley's Fund Led Solana ETF Inflows as SOL Passed $100
MSOL took 60% of a $9.1m day, extending a run that included the category's largest single session of the year.

Bitcoin's Bottom Signal Is Flashing. The Data Says Don't Rush.
VanEck's capitulation dashboard lit up — and its own history shows those clusters underperformed over the following three and six months.

Bitcoin Could Overtake Gold in the Next Bull Run, Says CZ
The Binance founder told a Hong Kong audience the obstacle is institutional, not technical — and that the valuation gap has narrowed to roughly tenfold.
Discussion
0 commentsNo comments yet — be the first to weigh in.