← All Flash News

OneKey Founder Says Team ‘Hacked’ Ledger in Lab Test, Reproducing Transaction-Signing Flaw

Ledger hardware wallet pictured against a red-lit cybersecurity backdrop with a hooded figure using a laptop.

OneKey founder Yishi said the company’s Anzen security team “hacked” Ledger by reproducing a transaction-replacement vulnerability in Ledger Ethereum App 1.22.1. Ledger, however, said it found no evidence that the flaw was exploited in the wild.

Yishi said the team demonstrated a race condition between the app’s display logic and transaction buffer that could allow an attacker to replace a pending transaction while a user was reviewing legitimate transaction details. 

In the scenario described by Yishi, a user could approve transaction A while the device signed transaction B without displaying the substituted transaction.

Ledger separately disclosed the underlying issue as LSB 023. The company said some applications built with Ledger Secure SDK could continue receiving new APDU commands during on-screen confirmation, potentially causing the parameters displayed to a user to differ from those ultimately signed.

Ledger attributed the vulnerability to the SDK’s I/O handling rather than its device operating system or firmware. The company addressed the issue through app-level checks and SDK changes and released Secure SDK version 26.6.1 on Aug. 21. 

The accounts differ on which Ethereum App release fixed the vulnerability. Yishi said Ledger resolved the issue in version 1.22.3, while X Community Notes linked the flaw to a vulnerability that TestMachine reported on Aug. 22 and said Ledger fixed it in version 1.22.2.

Ledger said users must update the affected apps through Ledger Live because updating the device firmware alone does not fix the vulnerability.

Source: Yishi