OneKey founder announces his team has hacked Ledger, the largest hardware wallet.
Security & Exploits ·
The OneKey founder announced that his team successfully reproduced a transaction replacement attack against Ledger's Ethereum app version 1.22.1. The vulnerability stems from a race condition in how the app handles transaction display and buffering, allowing an attacker to swap out a transaction while a user reviews the original one on-device. In practice, a user might approve one transaction but unknowingly sign a different one without ever seeing it on their screen.
The team reconstructed the attack by building the vulnerable version's code themselves, resolving an infrastructure issue with the test environment, and demonstrating the full exploit chain. Ledger patched the flaw in Ethereum app version 1.22.3.
Users running older versions of the Ledger Ethereum app remain exposed to this attack vector. The specific conditions required to trigger the vulnerability in real-world conditions and whether any instances have exploited it remain unclear.