Ledger said it was not hacked after OneKey researchers reproduced a transaction-replacement vulnerability in an outdated Ethereum app. Ledger said it fixed the flaw in version 1.22.2, released August 13, before OneKey's post. Ledger said it found no evidence of exploitation outside a laboratory.