OneKey Founder Announces Discovery of Vulnerability in Ledger

cryptonews.ruPublished on 2026-08-28Last updated on 2026-08-28

Abstract

The founder and CEO of OneKey, Yishi Wang, announced that the OneKey Anzen team successfully replicated an attack that allows transaction substitution in the Ethereum app for Ledger hardware wallets. According to Wang, the vulnerability stemmed from an error in the interaction between how a transaction is displayed on the device's screen and the processing of that transaction. This flaw enabled a malicious actor to alter a transaction after it appeared on the Ledger's screen but before it was signed. A potential attack scenario is described: a user sees and approves transaction A on their Ledger screen, but at that moment, an attacker swaps it for a different transaction B, which the device then signs without the user's knowledge. "We hacked Ledger," Wang stated. The team reportedly reproduced the full attack chain in a lab environment, from transaction substitution to signing. The issue affected the Ledger Ethereum app version 1.22.1. The company has since addressed the vulnerability in version 1.22.3. Users with older versions of the app are advised to update.

The OneKey Anzen team has announced the successful reproduction of an attack that allows for the substitution of a transaction in the Ethereum application for Ledger hardware wallets. This was reported by the founder and CEO of OneKey, Yishi Wang.

According to him, the problem arose due to an error in the interaction between the display of the transaction on the device's screen and the process of its processing. As a result, an attacker could change the transaction after it had appeared on the Ledger screen, but before it was signed.

The scenario could look like this:

  • the user sees transaction A on the Ledger screen;
  • verifies and confirms it;
  • at this moment, the attacker substitutes it with transaction B;
  • the device signs transaction B, which the user did not see.

"We hacked Ledger," Wang stated.

According to him, the team independently reproduced the full attack scenario in laboratory conditions—from the moment of transaction substitution to its signing. The issue affected the Ethereum application for Ledger version 1.22.1. It is noted that the company has already fixed the vulnerability in version 1.22.3.

Users who are using an older version of the Ethereum application for Ledger are recommended to update.

Recall that earlier, an X user under the pseudonym x3ideRaven reported receiving a phishing email that masqueraded as a message from Trezor.

Related Questions

QWhat vulnerability was discovered in Ledger hardware wallets according to OneKey's founder?

AA vulnerability that allows an attacker to modify an Ethereum transaction after it appears on the Ledger's screen but before it is signed, effectively substituting one transaction for another without the user's knowledge.

QHow does the attack scenario on the Ledger device typically unfold?

AThe user sees and approves transaction A on the Ledger screen; at that moment, an attacker replaces it with transaction B; the device then signs transaction B, which the user never verified.

QWhich specific Ledger application and version was affected by this vulnerability?

AThe Ethereum application for Ledger, specifically version 1.22.1.

QWhat did OneKey's team claim to have successfully reproduced in a lab environment?

AThey claimed to have successfully reproduced the full attack scenario, from the transaction substitution to its final signing.

QWhat action did Ledger take to address the reported vulnerability, and what is the recommendation for users?

ALedger fixed the vulnerability in version 1.22.3 of its Ethereum application. Users with older versions are recommended to update their application.

Related Reads

Websea's Third Anniversary: The Adjustments and Choices of a Mid-Sized Exchange During an Industry Shakeout Period

Websea, a mid-sized cryptocurrency exchange, celebrated its third anniversary in 2026 amid a period of industry consolidation. While the crypto landscape broadens with TradFi, RWA, and stablecoins, several established exchanges have retreated. This highlights the challenge for mid-tier platforms: growth is not automatic and depends on liquidity, compliance, security, and user retention. Websea has recently focused on strategic product adjustments. Key initiatives include enhancing risk management tools like contract insurance and copy trading, expanding its asset offerings to include TradFi CFDs (gold, silver, indices, forex), launching a Proof of Reserves (PoR) system for transparency, and engaging in regional RWA development through events like a summit in Almaty. The article analyzes these moves. Risk management products aim to improve user experience and retention, but their long-term viability hinges on clear rules and sustainable mechanisms. Offering TradFi CFDs seeks to capture user engagement during crypto market lulls, though it introduces new operational complexities. The PoR report addresses transparency concerns, but its value depends on regular updates. Regional RWA exploration offers potential access to real-world assets but faces significant hurdles in legal structuring and productization. Ultimately, Websea's three-year mark showcases a strategy to compete by broadening tradable assets, strengthening risk and transparency features, and exploring niche opportunities. The critical test will be whether these adjustments translate into sustainable trading volume, lasting user loyalty, and verifiable business growth over time.

marsbit41m ago

Websea's Third Anniversary: The Adjustments and Choices of a Mid-Sized Exchange During an Industry Shakeout Period

marsbit41m ago

Trading

Spot
活动图片