OneKey Founder Announces Discovery of Vulnerability in Ledger

cryptonews.ru2026-08-28 tarihinde yayınlandı2026-08-28 tarihinde güncellendi

Özet

The founder and CEO of OneKey, Yishi Wang, announced that the OneKey Anzen team successfully replicated an attack that allows transaction substitution in the Ethereum app for Ledger hardware wallets. According to Wang, the vulnerability stemmed from an error in the interaction between how a transaction is displayed on the device's screen and the processing of that transaction. This flaw enabled a malicious actor to alter a transaction after it appeared on the Ledger's screen but before it was signed. A potential attack scenario is described: a user sees and approves transaction A on their Ledger screen, but at that moment, an attacker swaps it for a different transaction B, which the device then signs without the user's knowledge. "We hacked Ledger," Wang stated. The team reportedly reproduced the full attack chain in a lab environment, from transaction substitution to signing. The issue affected the Ledger Ethereum app version 1.22.1. The company has since addressed the vulnerability in version 1.22.3. Users with older versions of the app are advised to update.

The OneKey Anzen team has announced the successful reproduction of an attack that allows for the substitution of a transaction in the Ethereum application for Ledger hardware wallets. This was reported by the founder and CEO of OneKey, Yishi Wang.

According to him, the problem arose due to an error in the interaction between the display of the transaction on the device's screen and the process of its processing. As a result, an attacker could change the transaction after it had appeared on the Ledger screen, but before it was signed.

The scenario could look like this:

  • the user sees transaction A on the Ledger screen;
  • verifies and confirms it;
  • at this moment, the attacker substitutes it with transaction B;
  • the device signs transaction B, which the user did not see.

"We hacked Ledger," Wang stated.

According to him, the team independently reproduced the full attack scenario in laboratory conditions—from the moment of transaction substitution to its signing. The issue affected the Ethereum application for Ledger version 1.22.1. It is noted that the company has already fixed the vulnerability in version 1.22.3.

Users who are using an older version of the Ethereum application for Ledger are recommended to update.

Recall that earlier, an X user under the pseudonym x3ideRaven reported receiving a phishing email that masqueraded as a message from Trezor.

İlgili Sorular

QWhat vulnerability was discovered in Ledger hardware wallets according to OneKey's founder?

AA vulnerability that allows an attacker to modify an Ethereum transaction after it appears on the Ledger's screen but before it is signed, effectively substituting one transaction for another without the user's knowledge.

QHow does the attack scenario on the Ledger device typically unfold?

AThe user sees and approves transaction A on the Ledger screen; at that moment, an attacker replaces it with transaction B; the device then signs transaction B, which the user never verified.

QWhich specific Ledger application and version was affected by this vulnerability?

AThe Ethereum application for Ledger, specifically version 1.22.1.

QWhat did OneKey's team claim to have successfully reproduced in a lab environment?

AThey claimed to have successfully reproduced the full attack scenario, from the transaction substitution to its final signing.

QWhat action did Ledger take to address the reported vulnerability, and what is the recommendation for users?

ALedger fixed the vulnerability in version 1.22.3 of its Ethereum application. Users with older versions are recommended to update their application.

İlgili Okumalar

The Pioneer of AI Boomerang Job-Hopping: No Ph.D., Fought Over by Top AI Labs in Silicon Valley

"AI's Boomerang Hire: The Unconventional Career of Barret Zoph Who is known as the first practitioner of 'boomerang hiring' in AI? Barret Zoph, now a Research VP at Google DeepMind, has an unconventional resume: former Senior Research Scientist at Google Brain, former VP of Post-Training Research at OpenAI, former co-founder/CTO of Thinking Machines Lab, former OpenAI Codex commercialization lead—all without a PhD. Zoph's career began at Google Brain in 2016 after his USC bachelor's degree. He co-authored the seminal "Neural Architecture Search with Reinforcement Learning," helping pioneer the NAS field. His later work included co-authoring the Switch Transformer, a key model for trillion-parameter scale training. He joined OpenAI in 2022, rising to VP focusing on reinforcement learning for post-training—a crucial step in aligning models like ChatGPT. USC later listed him among alumni who "paved the path for ChatGPT." In 2025, he co-founded Thinking Machines Lab with ex-OpenAI CTO Mira Murati but left under controversial circumstances less than a year later, returning briefly to OpenAI before his final move back to Google in 2026. His hiring coincides with significant talent churn at Google DeepMind. Data shows DeepMind's senior talent inflow/outflow ratio has sharply declined from 12:1 in 2023 to 2:1 in 2026, meaning for every two hires, one leaves—a stark contrast to Anthropic (22:1) and OpenAI (5.7:1). Key departures include founders and Nobel laureates moving to rivals. This fluid, sports-like transfer market for elite AI researchers is driven not just by pay but by competitive positioning, pre-IPO equity at startups, and concerns over shifting research priorities at large firms like Google as they focus more on commercial products like Gemini."

marsbit29 dk önce

The Pioneer of AI Boomerang Job-Hopping: No Ph.D., Fought Over by Top AI Labs in Silicon Valley

marsbit29 dk önce

Bitcoin Stabilizes at $80,000, How Do Institutions and Smart Money View the Future Market?

Bitcoin has consolidated around the $80,000 level following a record-breaking weekly dollar gain, pushing the price up 23.5% from August 17-23. Market focus is now on whether it can decisively overcome a significant resistance cluster between $81,000 and $86,000. This zone represents a critical supply wall, containing nearly 8% of the circulating supply and the average cost basis for major US spot Bitcoin ETFs. Analysis from Glassnode indicates the recent rally was fueled by substantial spot buying, evidenced by ETF inflows and declining exchange balances, rather than excessive leverage. Futures open interest has decreased, with cash/stablecoin margins dominating. While US ETF flows remain a key bullish driver, the market faces a crucial test. A successful break above the $81k-$82k resistance and the 50-week moving average (approx. $81,081) could signal a broader trend reversal. Failure may lead to a retracement toward the $75,000 support level. Institutional views are mixed but generally cautious. CryptoQuant highlights potential seasonal weakness in September, while CoinShares sees a likely trading range, requiring weaker jobs data for a sustained push toward $100k. K33 Research draws parallels to past cycle starts, and Bitwise suggests the bottoming process is advanced. Overall, the market is at a pivotal point, with the battle around $80k determining the near-term direction.

marsbit44 dk önce

Bitcoin Stabilizes at $80,000, How Do Institutions and Smart Money View the Future Market?

marsbit44 dk önce

İşlemler

Spot
活动图片