OneKey’s in-house security team said it successfully reproduced an exploit targeting an outdated version of Ledger’s on-device Ethereum application in a test environment. According to Cointelegraph, OneKey founder and CEO Yishi Wang said the team carried out a “transaction replacement attack” against Ledger Ethereum app 1.22.1 by using a previously patched vulnerability that allowed an attacker to overwrite the transaction waiting to be signed while the user was still reviewing the legitimate transaction. Ledger said the exploit required control over communications between the device and its host, including through malware, compromised wallet software or a hostile webpage. The company added app-level safeguards with Ethereum app 1.22.2 released on Aug. 13, before fixing the underlying issue in Secure SDK 26.6.1 on Aug. 21. Ledger also said in a Thursday X post that no Ledger user was hacked and that the issue described was a lab reproduction of a vulnerability in an outdated version of the Ethereum app.

The security test came after the Coldcard exploit in July, when attackers used a firmware bug introduced in March 2021 that weakened seed randomness on some Coldcard wallets and left the resulting private keys vulnerable to brute-force attacks. Ledger had previously said its devices were not affected by the Coldcard vulnerability because recovery phrases are generated using a certified source of randomness built into the device’s security chip. Ledger said the vulnerability reproduced by OneKey is unrelated to seed generation and instead affects how transactions are handled during the signing process.