Ledger Says Ethereum App Vulnerability Was Already Patched Before OneKey’s Public Disclosure
OneKey security researchers reproduced a transaction-replacement flaw in Ledger's hardware wallet, but the company says the fix was already live before the findings went public—and no users were harmed.
The Flaw and How It Works
OneKey announced on Thursday that its security team had successfully reconstructed an attack against version 1.22.1 of Ledger’s Ethereum application. The vulnerability centered on a race condition—a timing issue in how the software processed transaction information. In practical terms, an attacker positioned to intercept communications between a user’s device and computer could display one Ethereum transaction for approval while secretly replacing it with a different one before signing occurred. The substituted transaction would transfer funds to the attacker’s address without any indication of the swap appearing on the Ledger device’s screen. Executing such an attack would require the hacker to first compromise the pathway between device and host through malware, a manipulated wallet interface, or a hostile website.
Ledger’s Proactive Response
According to Ledger, the company had already identified and resolved the flaw through its internal security process. The fix shipped in Ethereum app version 1.22.2 on August 13—more than two weeks before OneKey went public with its demonstration. Ledger’s Chief Technology Officer characterized OneKey’s move as testing an outdated codebase and argued this didn’t constitute evidence of a successful “hack.” The company reported no instances of the vulnerability being exploited against actual users, and no evidence suggests attackers discovered and weaponized the flaw in the wild.
Beyond the initial patch, Ledger implemented deeper remediation. The company addressed the underlying cause in Secure SDK version 26.6.1 on August 21 and rebuilt dependent applications with the corrected code. Current recommendations direct users toward Ethereum app version 1.22.3 or later, which addresses both the transaction-replacement vulnerability and a separate transaction-display flaw identified through the same security review. Ledger published formal notification of these fixes on August 27.
The Broader Ecosystem Lesson
Ledger’s internal security division, Ledger Donjon, emphasized that the incident underscores why hardware wallets require the ability to receive regular software updates. As cryptocurrency custody solutions mature, the capacity to patch discovered weaknesses quickly has become a competitive advantage. The episode demonstrates that even established players face ongoing scrutiny, and rapid remediation channels matter significantly to protecting users. Swift vulnerability remediation by established wallet providers is essential for maintaining user confidence in hardware wallet infrastructure across the crypto market.
Source: Ledger, via Decrypt. Not financial advice.