Keyboard shortcuts

Aug 27, 2026, 08:29 PM UTC
Crypto // Security

Ledger Says It Wasn't Hacked. A Rival Reproduced the Bug Anyway.

OneKey's security team recreated a transaction-replacement attack against an outdated version of Ledger's Ethereum app.

peatpost Desk
Aggregated
Aug 27, 2026, 06:16 PM UTC3 min read
Ledger Says It Wasn't Hacked. A Rival Reproduced the Bug Anyway.
SourceDecrypt· 2h ago

The hardware wallet maker Ledger has rejected claims that it was hacked, after researchers at the rival wallet manufacturer OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger's Ethereum app.

Yishi Wang, founder and chief executive of OneKey, said the company's Anzen security team had recreated the attack against Ethereum app version 1.22.1 in a laboratory setting.

What the flaw does

"The bug is a race condition between the transaction display logic and the underlying transaction buffer," Wang wrote. "An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one."

That description matters, because it attacks the single feature a hardware wallet exists to provide.

The entire premise of a device like this is that the screen is trustworthy. A user's computer may be fully compromised, but the wallet displays the transaction independently, and the user confirms what they can see. If the displayed transaction can be swapped for a different one in the interval between display and signature, the guarantee collapses — a user would approve a legitimate payment and authorise a transfer to an attacker's address, with no indication on the device that anything had changed.

A Ledger hardware wallet deviceThe Ledger Flex. Hardware wallets rely on the device screen being a trustworthy display of what is actually being signed. Image: Decrypt/Ledger

Ledger's position

The company's response rests on two points: the vulnerability was patched before any exploit occurred, and the version OneKey tested is outdated.

Both are meaningful. A responsibly disclosed and fixed flaw is the security process working, and there is no evidence of user funds being taken. Reproducing a patched bug in a lab demonstrates that the bug was real, not that anyone is currently at risk.

The part that is genuinely uncomfortable

The complication is that hardware wallet users do not update automatically, and many deliberately avoid it.

The security culture around these devices encourages caution about firmware and app updates, on the reasonable grounds that an update is itself a moment of trust — and users who set up a wallet years ago, moved it to cold storage and left it alone are precisely the population least likely to be running current software.

A patched vulnerability protects everyone who has installed the patch. For a category of device explicitly marketed for long-term, hands-off storage, that is a smaller set of people than it would be for a phone app.

The competitive dimension

It is worth noting who published this. OneKey is a direct competitor, and vulnerability research by rivals occupies an awkward position in security disclosure.

The work appears technically sound and the flaw appears to have been real. It was also released publicly, with a video demonstration, in a way that maximises attention on a competitor's product rather than on the fix. Both things can be true, and the crypto hardware market has a long history of firms publicising each other's weaknesses.

For users the practical answer is unglamorous and unchanged: check which app version your device is running, and update it. The threat model these devices defend against assumes your computer is already hostile, and that assumption only holds if the device itself is current.

Written by
peatpost Desk
Aggregated · @peatpost
Share

Discussion

0 comments
0/2000

No comments yet — be the first to weigh in.

More from peatpost