OneKey Founder Announces Discovery of Vulnerability in Ledger

cryptonews.ruPublicado em 2026-08-28Última atualização em 2026-08-28

Resumo

The founder and CEO of OneKey, Yishi Wang, announced that the OneKey Anzen team successfully replicated an attack that allows transaction substitution in the Ethereum app for Ledger hardware wallets. According to Wang, the vulnerability stemmed from an error in the interaction between how a transaction is displayed on the device's screen and the processing of that transaction. This flaw enabled a malicious actor to alter a transaction after it appeared on the Ledger's screen but before it was signed. A potential attack scenario is described: a user sees and approves transaction A on their Ledger screen, but at that moment, an attacker swaps it for a different transaction B, which the device then signs without the user's knowledge. "We hacked Ledger," Wang stated. The team reportedly reproduced the full attack chain in a lab environment, from transaction substitution to signing. The issue affected the Ledger Ethereum app version 1.22.1. The company has since addressed the vulnerability in version 1.22.3. Users with older versions of the app are advised to update.

The OneKey Anzen team has announced the successful reproduction of an attack that allows for the substitution of a transaction in the Ethereum application for Ledger hardware wallets. This was reported by the founder and CEO of OneKey, Yishi Wang.

According to him, the problem arose due to an error in the interaction between the display of the transaction on the device's screen and the process of its processing. As a result, an attacker could change the transaction after it had appeared on the Ledger screen, but before it was signed.

The scenario could look like this:

  • the user sees transaction A on the Ledger screen;
  • verifies and confirms it;
  • at this moment, the attacker substitutes it with transaction B;
  • the device signs transaction B, which the user did not see.

"We hacked Ledger," Wang stated.

According to him, the team independently reproduced the full attack scenario in laboratory conditions—from the moment of transaction substitution to its signing. The issue affected the Ethereum application for Ledger version 1.22.1. It is noted that the company has already fixed the vulnerability in version 1.22.3.

Users who are using an older version of the Ethereum application for Ledger are recommended to update.

Recall that earlier, an X user under the pseudonym x3ideRaven reported receiving a phishing email that masqueraded as a message from Trezor.

Perguntas relacionadas

QWhat vulnerability was discovered in Ledger hardware wallets according to OneKey's founder?

AA vulnerability that allows an attacker to modify an Ethereum transaction after it appears on the Ledger's screen but before it is signed, effectively substituting one transaction for another without the user's knowledge.

QHow does the attack scenario on the Ledger device typically unfold?

AThe user sees and approves transaction A on the Ledger screen; at that moment, an attacker replaces it with transaction B; the device then signs transaction B, which the user never verified.

QWhich specific Ledger application and version was affected by this vulnerability?

AThe Ethereum application for Ledger, specifically version 1.22.1.

QWhat did OneKey's team claim to have successfully reproduced in a lab environment?

AThey claimed to have successfully reproduced the full attack scenario, from the transaction substitution to its final signing.

QWhat action did Ledger take to address the reported vulnerability, and what is the recommendation for users?

ALedger fixed the vulnerability in version 1.22.3 of its Ethereum application. Users with older versions are recommended to update their application.

Leituras Relacionadas

Transaction Substitution Vulnerability Discovered in Ledger's Ethereum Application

A vulnerability involving transaction substitution has been identified and confirmed in the Ethereum application for Ledger hardware wallets. The issue was a race condition between the transaction data displayed on the device's screen and the buffer holding the actual transaction data. This flaw allowed a malicious actor to overwrite a pending transaction while the user was reviewing a legitimate one on the display, potentially leading to the signing of an unseen transaction. The vulnerability was independently discovered by multiple parties. On August 22, 2026, researcher TestMachine disclosed it after detection by the Azimuth scanning tool. Later, on August 27, OneKey's founder Yishi Wang announced his team had successfully replicated the attack in a lab environment on app version 1.22.1. Ledger's security team, Donjon, responded that no real-world exploits or user losses occurred. They stated the flaw was internally identified and patched in Ethereum app version 1.22.2, released on August 13, 2026—prior to the public disclosures. An update to the underlying Ledger Secure SDK (v26.6.1) followed on August 21. Official security bulletin LSB 023, published August 27, details the vulnerability as residing in the SDK's I/O handling. While there is minor public discrepancy over whether version 1.22.2 or 1.22.3 fully resolved the issue, all parties strongly urge users to update their Ethereum application to the latest version via Ledger Live. The incident highlights a critical security principle: the safety of a hardware wallet depends on the entire chain of components—firmware, SDK, and applications—with a flaw in any link compromising the overall system.

cryptonews.ruHá 5m

Transaction Substitution Vulnerability Discovered in Ledger's Ethereum Application

cryptonews.ruHá 5m

Trading

Spot
活动图片