NewsCryptoOneKey Reproduces Transaction Replacement Attack on Outdated Ledger Ethereum App

OneKey Reproduces Transaction Replacement Attack on Outdated Ledger Ethereum App

Author: Cointelegraph·

Key Takeaways

  • OneKey's team reproduced a transaction replacement attack against Ledger's Ethereum app version 1.22.1 in a test environment.
  • The flaw could let attackers overwrite a pending transaction while the user was still reviewing it on the device screen.
  • Ledger stated exploitation required control over device-host communications and that no users were actually hacked.
  • Ledger added app-level safeguards on Aug. 13 with Ethereum app 1.22.2 and fixed the underlying issue in Secure SDK 26.6.1 on Aug. 21.
  • The disclosure follows the July Coldcard exploit and reflects increased independent testing of hardware wallet security claims.
OneKey Reproduces Transaction Replacement Attack on Outdated Ledger Ethereum App

The in-house security team at open-source hardware wallet provider OneKey says it has successfully reproduced an exploit targeting an outdated version of Ledger’s on-device Ethereum application in a test environment.

OneKey founder and CEO Yishi Wang said the team executed a “transaction replacement attack” against Ledger Ethereum app version 1.22.1 by exploiting a previously patched vulnerability that could allow attackers to overwrite the transaction waiting to be signed while the user was still reviewing the legitimate transaction on screen. Ledger devices are hardware wallets that require users to physically confirm transactions before they are broadcast to a blockchain. Transaction replacement attacks are notable in this context because they target the trust model that hardware wallets are built on — the assumption that what a user verifies on the device screen is exactly what gets signed and broadcast.

Responding to the research, Ledger said that exploiting the vulnerability required control over communications between the device and its host computer — for example, through malware, compromised wallet software, or a hostile webpage. The company added app-level safeguards with Ethereum app version 1.22.2, released on Aug. 13, before fixing the underlying issue in Secure SDK 26.6.1 on Aug. 21. The incident is a reminder that even hardware wallets depend on up-to-date firmware and companion applications, since vulnerabilities are typically only exploitable on outdated versions.

“No Ledger user was hacked. What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app,” Ledger wrote in a post on X: https://x.com/Ledger/status/2093007184779006334

The security test comes after the Coldcard exploit disclosed in July, in which attackers exploited a firmware bug introduced in March 2021 that weakened seed randomness on some Coldcard wallets, leaving the resulting private keys vulnerable to brute-force attacks.

Ledger had previously stated that its devices were not affected by the Coldcard vulnerability because recovery phrases are generated using a certified source of randomness built into the device’s security chip.

The vulnerability reproduced by OneKey is unrelated to seed generation and instead affects how transactions are handled during the signing process. Together, the disclosures have contributed to heightened scrutiny of hardware wallet security across the industry, with independent researchers increasingly testing vendor claims in lab environments rather than relying solely on vendor audits.