No, Ledger wasn’t hacked — a patched Ethereum app bug was reproduced in a lab, the company says Ledger has pushed back on claims that it was hacked after rival wallet maker OneKey demonstrated a transaction-replacement vulnerability against an outdated Ethereum app in a controlled environment. What happened - OneKey founder Yishi Wang posted on X that his company’s Anzen security team was able to recreate a race-condition bug in Ledger’s Ethereum app version 1.22.1. The flaw, he said, allowed an attacker to overwrite a transaction that a user was reviewing: “An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.” - In practice, that could let an attacker who controls the communication channel between a Ledger device and its host (via malware, a compromised wallet app, or a malicious website) display a legitimate Ethereum transaction on the device while replacing its actual contents with a different transaction that redirects funds to the attacker. Ledger’s response and timeline - Ledger CTO Charles Guillemet rejected the suggestion that reproducing an already-fixed issue is equivalent to “hacking Ledger.” He noted the bug affected an outdated app version and said it was fixed before OneKey’s post. - Ledger says it added safeguards in Ethereum app 1.22.2 (released August 13) and fixed the underlying issue in Secure SDK 26.6.1 (released August 21). The company rebuilt its apps with the corrected SDK and recommends users run Ethereum app version 1.22.3 or later (which also addresses a separate transaction-display issue). - Ledger published a security bulletin on August 27 saying the bug could cause a device to show one transaction while signing another, but that exploitation would require an attacker to control device-host communications. The company reported no evidence of exploitation in the wild: “No user was hacked. No exploitation in the wild,” Guillemet wrote. Why this matters for hardware wallets - Ledger’s internal Donjon security team emphasized the point that updateability is essential: all software can have bugs, and the ability to patch devices in the field is a core security feature for hardware wallets. A device that can’t be updated can’t be fixed, the team wrote on X. - The episode underscores that even hardware wallets are not immune to software bugs — but it also highlights the benefit of a quick patch-and-distribute cycle when issues are found. Practical advice for users - Ledger urges customers to: - Install the latest firmware and apps via Ledger Live (apps and firmware update separately). - Update the Ethereum app to version 1.22.3 or later and verify the app version on the device. - Remember: an attacker still needs to compromise the host environment (PC, mobile, browser) or the wallet software to exploit this class of bug — keeping host systems secure and installing updates promptly reduces risk. Context - This comes after a high-profile attack earlier in August in which more than $130 million in Bitcoin was stolen from users of Coldcard air-gapped wallets. Ledger’s Donjon lab exists to probe and harden Ledger products before attackers can. Bottom line: researchers reproduced a transaction-replacement flaw in an old Ethereum app version in a lab setting; Ledger says it patched the issue weeks earlier and found no evidence of real-world exploitation. Users should update firmware and apps and keep their host environments secure. Read more AI-generated news on: undefined/news
