Ledger Patches Transaction Replacement Vulnerability After OneKey Security Lab Reproduction
OneKey security researchers successfully reproduced a transaction replacement attack against an outdated Ledger Ethereum app, but no user funds were compromised and Ledger has already patched the vulnerability.
OneKey Reproduces Transaction Replacement Attack
The security team at open-source wallet provider OneKey has successfully reproduced a transaction replacement vulnerability affecting older versions of Ledger’s Ethereum application. According to OneKey founder and CEO Yishi Wang, the security team executed a targeted exploit against Ledger Ethereum app version 1.22.1 in a controlled laboratory environment. The attack demonstrates a critical flaw in how the outdated application handles user transactions during the signing process. Rather than targeting the generation of private keys or recovery phrases, this vulnerability allows attackers to manipulate transactions while users are actively reviewing them on their devices. Specifically, the exploit enables attackers to replace a legitimate transaction with a malicious alternative before the user completes their cryptographic signature approval.
Attack Requirements and Ledger’s Rapid Response
Exploiting this vulnerability demands that attackers first establish control over the communication channel between a Ledger hardware wallet and the computer it connects to. According to Ledger’s technical assessment, this level of device control could be achieved through several vectors, including malware infections on the user’s computer, compromised cryptocurrency wallet software, or malicious webpages. Recognizing the security risk, Ledger implemented a multi-stage fix. On August 13, the company released Ethereum app version 1.22.2, which introduced app-level safeguards to defend against the exploitation technique. Subsequently, on August 21, Ledger addressed the underlying architectural issue by releasing Secure SDK version 26.6.1, providing a comprehensive foundation-level fix that eliminates the vulnerability at its root. The company emphasized that no Ledger user suffered any loss of funds as a result of this vulnerability, and the flaw only affects users who have not updated to the current application version.
Broader Hardware Wallet Security Landscape
OneKey’s security disclosure arrives against a backdrop of heightened scrutiny regarding hardware wallet security practices. Just weeks earlier, in July, the cryptocurrency community discovered a separate but serious vulnerability affecting Coldcard hardware wallets. That exploit leveraged a firmware bug that was inadvertently introduced in March 2021, which resulted in weakened randomness during the seed generation process. The compromised randomness left private keys potentially vulnerable to brute-force attacks by adversaries with sufficient computational resources. Ledger differentiated its security architecture by explaining that its devices incorporate a certified source of randomness built into the device’s security chip specifically to prevent such seed generation vulnerabilities. The Ledger hardware was not affected by the Coldcard incident. However, the OneKey vulnerability reproduced in this case differs fundamentally—it does not compromise seed generation or private key creation, but rather focuses on manipulating transaction data during the signing authorization phase. This distinction is important because it illustrates that security threats in the cryptocurrency ecosystem can emerge from multiple attack surfaces within hardware wallet systems.
Source: Cointelegraph. Not financial advice.