Summary
- OneKey demonstrated a transaction-replacement vulnerability using Ledger’s outdated Ethereum app version 1.22.1.
- Ledger asserts that the vulnerability was resolved in version 1.22.2 prior to OneKey's announcement and has found no evidence of user attacks.
- Users are advised to update to Ethereum app version 1.22.3 or higher and verify their app's version on their devices.
Ledger, the cryptocurrency wallet manufacturer, has dismissed allegations of being hacked following an experiment by OneKey, a competing wallet developer, which successfully replicated a transaction-replacement vulnerability in an earlier version of Ledger’s Ethereum application.
On Thursday, Yishi Wang, the founder and CEO of OneKey, announced on X that their Anzen security team had recreated the attack using Ledger’s Ethereum app version 1.22.1 in a controlled environment.
Wang explained, “The bug is a race condition between the transaction display logic and the underlying transaction buffer. An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.”
This means that if a hacker managed to infiltrate the software interacting with a vulnerable Ledger app, they could present a legitimate transaction to the user and then alter its details before the user signs it, potentially diverting funds to the hacker’s wallet without any visible changes on the device.
However, Ledger's Chief Technology Officer, Charles Guillemet, rebuffed OneKey's claims, asserting that replicating a previously patched bug does not equate to hacking. He stated, “What this thread describes is a vulnerability in an outdated version of the Ethereum app. It was identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post.”
In a security bulletin issued on Thursday, Ledger clarified that the identified flaw could lead to a situation where a compromised app displays one transaction while signing another. For this to occur, an attacker would first need to take control of the communication between the device and its host via malware, a compromised wallet application, or a malicious website.
Ledger confirmed that there is no indication that this vulnerability had been exploited in real-world scenarios. Guillemet reiterated, “No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding.”
Ledger implemented additional security measures in Ethereum app version 1.22.2 on August 13, followed by addressing the core issue in Secure SDK version 26.6.1 on August 21, and subsequently rebuilt its applications with the updated software. The company now recommends users upgrade to version 1.22.3 or later, which also remedies a separate transaction-display vulnerability. Ledger's bulletin was published on August 27.
When questioned about OneKey’s assertions, Ledger referred to its internal security research team, Ledger Donjon, which stated in a separate post on X that the incident highlights the necessity for hardware wallets to support software updates. They remarked, “All software has bugs. Hardware wallets are no exception. That’s why updateability is a core part of Ledger’s security architecture: when a vulnerability is found, whether by our own Donjon team or by external researchers, we can patch every device in the field. A wallet that can’t be updated can’t be fixed.”
Ledger urged its customers to ensure they are using the latest firmware and applications through Ledger Wallet, update the Ethereum app to version 1.22.3 or later, and confirm the version displayed on their devices, noting that apps and firmware are updated separately.
Earlier this month, following an incident in which attackers stole over $130 million in Bitcoin from users of Coldcard air-gapped wallets, Guillemet remarked to Decrypt that this should serve as a cautionary tale for the hardware wallet industry. He added, “We also don't just rely on our own word for it. Our Donjon research lab exists to try to break our products before anyone else can.”
