Particle.news
Download on the App Store

Ledger Says It Patched Ethereum App Bug Before OneKey Reproduced It

Ledger says an app update followed by a Secure SDK patch stops a race condition that could let a compromised host swap transactions.

Overview

  • OneKey’s Anzen team reproduced a transaction‑replacement attack against Ledger’s Ethereum app version 1.22.1 in a laboratory on Aug. 27–28, showing a race condition that could let the device display one transaction while signing another.
  • Ledger says it added application state checks in Ethereum app 1.22.2 on Aug. 13 and released Secure SDK 26.6.1 on Aug. 21, after which apps were rebuilt and Ledger began recommending Ethereum app 1.22.3 or later.
  • The flaw lives in application‑level handling of APDU commands and requires an attacker to control the connection between the Ledger device and its host through malware, a compromised wallet app, or a hostile webpage; it cannot be triggered remotely against an unplugged device.
  • Ledger reports no evidence of exploitation in the wild, rejects claims that the company was 'hacked' for this issue, and says the lab reproduction targeted an outdated app that had already been fixed.
  • Users should update apps through Ledger Live and check the on‑device Ethereum app version while third‑party developers must rebuild apps with Secure SDK 26.6.1 or later because firmware updates alone do not replace vulnerable applications, a requirement that highlights the security value of updateable hardware wallets.