Ledger patches transaction-swap flaw found by rival wallet maker's security team
Security & Exploits ·
OneKey's Anzen research team says it reproduced a lab attack that could let a hidden transaction replace one a Ledger user believes they are approving, a flaw Ledger has since patched.
The team behind OneKey said it reproduced a transaction-replacement attack against the Ledger Ethereum app version 1.22.1 inside its own lab, describing the underlying issue as a race condition between the app's transaction display logic and the transaction buffer holding the data waiting to be signed. According to the researchers, the flaw meant an attacker could overwrite the pending transaction while a user was still reviewing what appeared on their device screen. In practice, the team said, a user could see and approve one transaction on their Ledger while the device actually signed a different one that was never shown to them.
To confirm the bug, OneKey's researchers said they built the 1.22.1 firmware image themselves, worked around a reset error in Ledger's testing emulator, and ran the full attack sequence end to end in a controlled environment. They said Ledger had already addressed the issue in Ethereum app version 1.22.3 and urged anyone still running an older build to update.
Ledger's own security team pushed back on characterizations of the disclosure, and coverage of the episode noted the fix had been rolled into SDK v26.6.1 with Ledger's Donjon team stating there was no evidence the vulnerability had been exploited against real users. A separate report framed the incident more bluntly, arguing that despite the "we hacked Ledger" framing, the device itself was not compromised in the wild and that the flaw was a lab-reproduced software issue rather than an active breach. Other outlets covering the disclosure similarly noted that Ledger said the vulnerability had already been patched before the exploit details were made public.
Four distinct sources have now reported on the disclosure, with consistent details on the affected app version, the race-condition mechanism, and the 1.22.3 fix, though accounts differ on how the finding should be characterized publicly. What remains unconfirmed is whether any user ever encountered the bug outside a controlled lab setting, and how many Ledger Ethereum app installations remained on vulnerable versions at the time of disclosure. Users running affected hardware are advised to confirm they are on app version 1.22.3 or later.