The OneKey Anzen team has announced the successful reproduction of an attack that allows for the substitution of a transaction in the Ethereum application for Ledger hardware wallets. This was reported by the founder and CEO of OneKey, Yishi Wang.
According to him, the problem arose due to an error in the interaction between the display of the transaction on the device's screen and the process of its processing. As a result, an attacker could change the transaction after it had appeared on the Ledger screen, but before it was signed.
The scenario could look like this:
- the user sees transaction A on the Ledger screen;
- verifies and confirms it;
- at this moment, the attacker substitutes it with transaction B;
- the device signs transaction B, which the user did not see.
"We hacked Ledger," Wang stated.
According to him, the team independently reproduced the full attack scenario in laboratory conditions—from the moment of transaction substitution to its signing. The issue affected the Ethereum application for Ledger version 1.22.1. It is noted that the company has already fixed the vulnerability in version 1.22.3.
Users who are using an older version of the Ethereum application for Ledger are recommended to update.
Recall that earlier, an X user under the pseudonym x3ideRaven reported receiving a phishing email that masqueraded as a message from Trezor.





