NewsCryptoOneKey Says It Reproduced Transaction Replacement Attack on Outdated Ledger Ethereum App

OneKey Says It Reproduced Transaction Replacement Attack on Outdated Ledger Ethereum App

Author: CoinWy·

Key Takeaways

  • OneKey said it reproduced the attack on an older version of Ledger’s Ethereum application, not on the product line as a whole.
  • The reported issue involves transaction replacement, where the signed transaction can differ from what the user believes is being approved.
  • The public LedgerHQ repository and changelog allow outside parties to inspect version history and track changes to the Ethereum app.
  • The article says users should verify installed app versions and apply pending updates through Ledger Live.
  • The reporting does not confirm whether the behavior remains present in current releases or whether Ledger has issued a formal advisory.
OneKey Says It Reproduced Transaction Replacement Attack on Outdated Ledger Ethereum App

Hardware wallet maker OneKey says it reproduced a transaction replacement attack against an outdated version of Ledger’s Ethereum app, a claim that highlights the risks of running legacy firmware while stopping short of implicating current, updated software.

The report circulated through security researcher posts on X, where the reproduction of the issue was demonstrated against an older build of the Ledger Ethereum application. The claim remains narrowly scoped: it targets an outdated app version rather than the entire product line. For related coverage, see UK Government Reports 240 Crypto Millionaires in 2025.

What OneKey says it reproduced

A transaction replacement attack, in plain terms, refers to a scenario where the data a user believes they are signing is swapped for different transaction details before the signature is finalized. The risk is that a wallet screen could show one action while the device actually authorizes another. For related coverage, see Visa Works With Upbit Parent on Stablecoin Payments, AI Commerce.

Risks of this general kind are a long-running concern in hardware wallet security: because the computer or phone running the wallet software can itself be compromised, the device’s own screen is intended to serve as the last checkpoint for confirming what is actually being signed.

OneKey is credited as the party that reproduced the behavior, according to a researcher post on X describing the test. Because the reproduction was tied to an outdated Ledger Ethereum app, the finding demonstrates legacy-version risk rather than a confirmed flaw in the latest release. For related coverage, see Abu Dhabi Royal Backs 49% Stake in Trump-Linked Crypto Bank.

The underlying software is Ledger’s open-source Ethereum application, whose code and revision history are public in the LedgerHQ app-ethereum repository. That transparency allows outside developers, including competitors such as OneKey, to inspect and test behavior across versions.

Why the “outdated” qualifier matters

The key detail in the report is the software state of the app. The reproduction is described against an outdated build, which means the vulnerability framing depends on the version being used, not simply on the Ledger brand.

That distinction does not support a conclusion that every Ledger Ethereum app is affected. Ongoing changes to the application are tracked in the project’s public changelog, where fixes and feature updates are recorded over time. Whether the reproduced behavior persists in current builds is the open question the report itself does not resolve.

For readers, the practical takeaway is version awareness. A reproduced attack on legacy software says more about update hygiene than about the security of a fully patched device.

What it means for wallet users

A reproduced attack naturally raises questions about exposure, and the most direct user response is to verify which app version is installed and whether updates are pending. On Ledger devices, that check runs through Ledger Live, the companion software that manages installed blockchain apps and flags available updates. Hardware wallet security often depends on this kind of maintenance discipline rather than on any single headline flaw.

The cross-brand framing — a OneKey test against a Ledger app for Ethereum — gives the story industry-wide relevance around trust in transaction verification. Industry efforts have already moved in this direction: vendors including Ledger have promoted “clear signing,” which renders human-readable transaction fields on the device instead of opaque payloads, so that on-device verification carries real meaning. OneKey has also been active on the feature side, recently rolling out a tool to borrow gas fees for TRON transactions, underscoring the competitive backdrop against which these security disclosures land.

Security incidents across the sector continue to focus attention on how projects respond, from patch cadence to user compensation, as seen when The Sandbox pledged 1:1 repayment after a bridge exploit. In each case, the response to a disclosed issue often shapes user trust as much as the underlying technical detail.

Given the weak, single-source nature of the current reporting, the responsible reading is cautious: the demonstration is tied to an outdated app, and confirmation of scope, affected versions, and any vendor response remains outstanding, including whether a formal advisory or changelog entry follows.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.