XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Learn
● Learn

Ledger Patches Transaction Replacement Vulnerability After OneKey Security Lab Reproduction

OneKey security researchers successfully reproduced a transaction replacement attack against an outdated Ledger Ethereum app, but no user funds were compromised and Ledger has already patched the vulnerability.

JM
by Jacob Marquez · Learn Desk
Published August 28, 2026 · 3 min read

OneKey Reproduces Transaction Replacement Attack

The security team at open-source wallet provider OneKey has successfully reproduced a transaction replacement vulnerability affecting older versions of Ledger’s Ethereum application. According to OneKey founder and CEO Yishi Wang, the security team executed a targeted exploit against Ledger Ethereum app version 1.22.1 in a controlled laboratory environment. The attack demonstrates a critical flaw in how the outdated application handles user transactions during the signing process. Rather than targeting the generation of private keys or recovery phrases, this vulnerability allows attackers to manipulate transactions while users are actively reviewing them on their devices. Specifically, the exploit enables attackers to replace a legitimate transaction with a malicious alternative before the user completes their cryptographic signature approval.

Attack Requirements and Ledger’s Rapid Response

Exploiting this vulnerability demands that attackers first establish control over the communication channel between a Ledger hardware wallet and the computer it connects to. According to Ledger’s technical assessment, this level of device control could be achieved through several vectors, including malware infections on the user’s computer, compromised cryptocurrency wallet software, or malicious webpages. Recognizing the security risk, Ledger implemented a multi-stage fix. On August 13, the company released Ethereum app version 1.22.2, which introduced app-level safeguards to defend against the exploitation technique. Subsequently, on August 21, Ledger addressed the underlying architectural issue by releasing Secure SDK version 26.6.1, providing a comprehensive foundation-level fix that eliminates the vulnerability at its root. The company emphasized that no Ledger user suffered any loss of funds as a result of this vulnerability, and the flaw only affects users who have not updated to the current application version.

Broader Hardware Wallet Security Landscape

OneKey’s security disclosure arrives against a backdrop of heightened scrutiny regarding hardware wallet security practices. Just weeks earlier, in July, the cryptocurrency community discovered a separate but serious vulnerability affecting Coldcard hardware wallets. That exploit leveraged a firmware bug that was inadvertently introduced in March 2021, which resulted in weakened randomness during the seed generation process. The compromised randomness left private keys potentially vulnerable to brute-force attacks by adversaries with sufficient computational resources. Ledger differentiated its security architecture by explaining that its devices incorporate a certified source of randomness built into the device’s security chip specifically to prevent such seed generation vulnerabilities. The Ledger hardware was not affected by the Coldcard incident. However, the OneKey vulnerability reproduced in this case differs fundamentally—it does not compromise seed generation or private key creation, but rather focuses on manipulating transaction data during the signing authorization phase. This distinction is important because it illustrates that security threats in the cryptocurrency ecosystem can emerge from multiple attack surfaces within hardware wallet systems.

Source: Cointelegraph. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Learn Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.