The OneKey Anzen team successfully replicated a transaction replacement attack on Ledger's Ethereum application version 1.22.1 in a controlled environment.

we hacked ledger.

the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab.

the bug is a race condition between the transaction display logic and the underlying transaction buffer.

an attacker can… pic.twitter.com/feT3RnSMh2

— Yishi (@ohyishi) August 27, 2026

The vulnerability stemmed from a race condition between the transaction display logic and the transaction buffer, which could result in the device showing one transaction to the user while signing another.

Ledger's security team, Donjon, verified the existence of the vulnerability and confirmed that it was addressed in patch 1.22.2, released on August 13.

No Ledger user was hacked.

What's described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app.

The issue was already identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post. The…

— Ledger Donjon (@DonjonLedger) August 27, 2026

According to the company, no users were affected, as the vulnerability pertained to an outdated version of the app and the confirmed scenario was limited to a laboratory setting.

In its security bulletin, Ledger noted that the bug allowed a new APDU command to be sent while the user was confirming a previous operation on the screen. The company urged users to update their software and verify the current hardware firmware.

It's worth mentioning that on August 17, BitBox, a hardware wallet manufacturer, released an update called Dixence that resolved two major vulnerabilities found during internal audits using AI models.