NewsCryptoLedger Denies Hack Claims, Says Ethereum App Vulnerability Was Patched Before Exploit

Ledger Denies Hack Claims, Says Ethereum App Vulnerability Was Patched Before Exploit

Author: Decrypt·

Key Takeaways

  • OneKey's Anzen security team reproduced a transaction-replacement race condition vulnerability in Ledger's Ethereum app version 1.22.1 in a laboratory setting.
  • Exploiting the flaw required the attacker to have already compromised the host computer or the connection between the device and its software.
  • Ledger stated the vulnerability was fixed in Ethereum app 1.22.2 released on August 13, with the underlying issue addressed in Secure SDK version 26.6.1 on August 21.
  • Ledger said it found no evidence the vulnerability was exploited outside a laboratory and that no users were hacked.
  • Ledger recommends users update their Ethereum app to version 1.22.3 or later and install the latest firmware through Ledger Wallet.
Ledger Denies Hack Claims, Says Ethereum App Vulnerability Was Patched Before Exploit

Crypto wallet developer Ledger has rejected claims that it was hacked, after researchers at rival wallet maker OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger's Ethereum app.

On Thursday, Yishi Wang, founder and CEO of OneKey, said on X that the company's Anzen security team recreated the attack against Ethereum app version 1.22.1 in a lab.

"The bug is a race condition between the transaction display logic and the underlying transaction buffer," Wang wrote. "An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one."

Such a flaw would allow a hacker who had already compromised the software communicating with a vulnerable Ledger app to display a legitimate Ethereum transaction to the user, then swap its details before signing—redirecting funds to the attacker's wallet without the change appearing on the device. The prerequisite is significant: the vulnerability alone does not grant an attacker access, and exploiting it presupposes that the host computer or connection has already been compromised.

Ledger Chief Technology Officer Charles Guillemet rejected OneKey's characterization, arguing that reproducing an already-patched bug does not amount to "hacking Ledger."

"What this thread describes is a vulnerability in an outdated version of the Ethereum app," he responded on X. "It was identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post."

In a security bulletin published on Thursday, Ledger explained that the flaw could cause an affected app to display one transaction while signing another. Exploitation would first require an attacker to control communications between the device and its host—through malware, a compromised wallet app, or a hostile website.

Ledger said it found no evidence that anyone exploited the vulnerability outside a laboratory.

"No user was hacked. No exploitation in the wild," Guillemet wrote. "Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding."

According to the company, safeguards were added in Ethereum app version 1.22.2 on Aug. 13, before the underlying issue was addressed in Secure SDK version 26.6.1 on Aug. 21 and Ledger's apps were rebuilt with the corrected software. The company recommends version 1.22.3 or later, which also fixes a separate transaction-display vulnerability. The bulletin was published on Aug. 27.

When asked about OneKey's claims, Ledger pointed Decrypt to Ledger Donjon, the company's internal security research team, which said in a separate X post that the episode demonstrated why hardware wallets must support software updates.

"All software has bugs. Hardware wallets are no exception," the team wrote. "That's why updateability is a core part of Ledger's security architecture: when a vulnerability is found, whether by our own Donjon team or by external researchers, we can patch every device in the field. A wallet that can't be updated can't be fixed."

Ledger advised customers to install the latest firmware and apps through Ledger Wallet, update the Ethereum app to version 1.22.3 or later, and verify the version displayed on the device. Apps and firmware update separately.

Earlier this month, after attackers stole more than $130 million in Bitcoin from users of Coldcard air-gapped wallets, Guillemet told Decrypt that the incident served as a warning for the hardware wallet industry.

"We also don't just rely on our own word for it," he said. "Our Donjon research lab exists to try to break our products before anyone else can." The dispute between the two wallet makers unfolds against heightened scrutiny of hardware wallet security across the industry, and the immediate practical step for Ledger users is verifying that their Ethereum app is on version 1.22.3 or later.