OneKey Founder Announces Discovery of Vulnerability in Ledger

cryptonews.ruОпубліковано о 2026-08-28Востаннє оновлено о 2026-08-28

Анотація

The founder and CEO of OneKey, Yishi Wang, announced that the OneKey Anzen team successfully replicated an attack that allows transaction substitution in the Ethereum app for Ledger hardware wallets. According to Wang, the vulnerability stemmed from an error in the interaction between how a transaction is displayed on the device's screen and the processing of that transaction. This flaw enabled a malicious actor to alter a transaction after it appeared on the Ledger's screen but before it was signed. A potential attack scenario is described: a user sees and approves transaction A on their Ledger screen, but at that moment, an attacker swaps it for a different transaction B, which the device then signs without the user's knowledge. "We hacked Ledger," Wang stated. The team reportedly reproduced the full attack chain in a lab environment, from transaction substitution to signing. The issue affected the Ledger Ethereum app version 1.22.1. The company has since addressed the vulnerability in version 1.22.3. Users with older versions of the app are advised to update.

The OneKey Anzen team has announced the successful reproduction of an attack that allows for the substitution of a transaction in the Ethereum application for Ledger hardware wallets. This was reported by the founder and CEO of OneKey, Yishi Wang.

According to him, the problem arose due to an error in the interaction between the display of the transaction on the device's screen and the process of its processing. As a result, an attacker could change the transaction after it had appeared on the Ledger screen, but before it was signed.

The scenario could look like this:

  • the user sees transaction A on the Ledger screen;
  • verifies and confirms it;
  • at this moment, the attacker substitutes it with transaction B;
  • the device signs transaction B, which the user did not see.

"We hacked Ledger," Wang stated.

According to him, the team independently reproduced the full attack scenario in laboratory conditions—from the moment of transaction substitution to its signing. The issue affected the Ethereum application for Ledger version 1.22.1. It is noted that the company has already fixed the vulnerability in version 1.22.3.

Users who are using an older version of the Ethereum application for Ledger are recommended to update.

Recall that earlier, an X user under the pseudonym x3ideRaven reported receiving a phishing email that masqueraded as a message from Trezor.

Пов'язані питання

QWhat vulnerability was discovered in Ledger hardware wallets according to OneKey's founder?

AA vulnerability that allows an attacker to modify an Ethereum transaction after it appears on the Ledger's screen but before it is signed, effectively substituting one transaction for another without the user's knowledge.

QHow does the attack scenario on the Ledger device typically unfold?

AThe user sees and approves transaction A on the Ledger screen; at that moment, an attacker replaces it with transaction B; the device then signs transaction B, which the user never verified.

QWhich specific Ledger application and version was affected by this vulnerability?

AThe Ethereum application for Ledger, specifically version 1.22.1.

QWhat did OneKey's team claim to have successfully reproduced in a lab environment?

AThey claimed to have successfully reproduced the full attack scenario, from the transaction substitution to its final signing.

QWhat action did Ledger take to address the reported vulnerability, and what is the recommendation for users?

ALedger fixed the vulnerability in version 1.22.3 of its Ethereum application. Users with older versions are recommended to update their application.

Пов'язані матеріали

iPhone Owners Will Not Be Able to Use the Digital Ruble - Vedomosti

iPhone users in Russia will face obstacles in using the digital ruble, the country's central bank's new digital currency, according to a report by Vedomosti. The Bank of Russia's website states iOS device owners can only use the digital ruble with an updated banking app containing the necessary features. However, banks cannot upload these updated apps to the App Store by the September 1st deadline. The main hurdles are sanctions and technical requirements. Apple blocks apps from sanctioned Russian banks. Furthermore, the Bank of Russia mandates that apps use Russian cryptographic standards, connect to specific central bank domains and APIs. Apple identifies these technical elements as markers of affiliation with the Russian state financial infrastructure, leading to app rejection. Certified solutions already exist for Android. Apple's review process scrutinizes not just code but also the build's origin—including developer accounts, cryptographic keys, and network requests—which can lead to blocks for apps or entire developer accounts. While "guerrilla apps" or clones sometimes appear, they are typically removed from the App Store within days or hours. For iPhone users, some banks offer web-based access to digital ruble functions as an alternative. However, major banks like VTB, RSHB, and "Russia" told Vedomosti the digital ruble is only available in their Android apps. Starting September 1st, 12 systemically important Russian banks, including Sberbank, VTB, and Alfa-Bank, are required to provide access to the digital ruble, which must be integrated as a wallet within their own banking applications, not a separate app. Also from September, all major Russian companies are mandated to begin accepting digital ruble payments, with telecom operators and marketplaces announcing the service's launch.

cryptonews.ru10 хв тому

iPhone Owners Will Not Be Able to Use the Digital Ruble - Vedomosti

cryptonews.ru10 хв тому

In the Era of AI Transactions, How Do We Build a Trust System?

Title: In the AI Trading Era, How Do We Build a Trust System? Over a decade ago, the first online credit card purchase sparked a simple question: who do you trust? The answer was intermediary platforms that built trust between strangers. Each new era of commerce expands transactional boundaries between strangers and requires new intermediaries to foster trust, from ancient credit systems to modern e-commerce ratings. Now, the machine age is here. With AI agents autonomously executing transactions—from booking trips to managing payments—at speeds and scales beyond human oversight, a critical question arises: who is liable when a non-human entity acts outside the rules? These agents are anonymous, mutable code, making traditional trust models based on human or corporate accountability obsolete. The core challenge is establishing verifiable, non-transferable identity and reputation for AI agents. Current solutions like the ERC-8004 standard provide a public, permanent identity record but suffer from a flaw: the identity is a tradable NFT, allowing reputation to be bought, sold, and potentially weaponized by bad actors. A new "trust stack" is emerging to fill this gap, moving beyond simple scoring to bind reputation inseparably to the agent. Key approaches include: * **Skyfire:** Issues signed identity tokens cryptographically linking the agent, its development platform, and its human sponsor, ensuring traceable accountability and integrating payment. * **RNWY:** Uses non-transferable "Soulbound Tokens" (ERC-5192) to permanently bind reputation to an agent's wallet. Abandoning a tarnished reputation requires discarding the entire wallet and its history, creating a high cost for misconduct. * **ChainAware:** Foregoes issuing credentials, instead generating credit scores based on a wallet's on-chain behavior history to preemptively assess risk, similar to bank fraud detection. The lesson is that no single solution suffices. A robust trust infrastructure requires a layered stack: a base layer for sponsor accountability, a middle layer ensuring non-transferable identity/reputation, and a top layer for behavior-based scoring. As in past cycles, the intermediaries that solve the trust problem for this new era of AI-driven commerce will capture significant value. The ultimate trajectory of the agent economy depends on the trust systems we build now.

marsbit15 хв тому

In the Era of AI Transactions, How Do We Build a Trust System?

marsbit15 хв тому

Торгівля

Спот
活动图片