Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ledger rejects hack claim after OneKey recreates bug

    August 28, 2026

    Trump crypto ventures left investors $4.7B underwater: report

    August 28, 2026

    Mirae Asset targets $109B digital asset business

    August 28, 2026
    Facebook X (Twitter) Instagram
    Cryptify Now
    • Home
    • Features
      • Typography
      • Contact
      • View All On Demos
    • Typography
    • Buy Now
    X (Twitter) Instagram YouTube LinkedIn
    Cryptify Now
    You are at:Home » Ledger rejects hack claim after OneKey recreates bug
    Crypto

    Ledger rejects hack claim after OneKey recreates bug

    James WilsonBy James WilsonAugust 28, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Ledger rejected claims that it had been hacked after OneKey’s Anzen security team reproduced a transaction replacement flaw against an outdated version of Ledger’s Ethereum application.

    Summary

    • OneKey reproduced a transaction substitution attack against Ledger Ethereum app version 1.22.1 in laboratory testing.
    • Ledger says Ethereum app 1.22.2 added safeguards before OneKey publicly described its reproduction attempt online.
    • An attacker needed control over device-host communications through malware, hostile webpages or compromised wallet software.
    • Secure SDK version 26.6.1 blocked interleaved commands before they reached individual Ledger device applications directly.
    • Ledger found no evidence the vulnerability was exploited against users or caused cryptocurrency losses anywhere.

    OneKey founder Yishi Wang said on Aug. 27 that researchers completed the attack against Ethereum app 1.22.1 in a laboratory. Ledger confirmed the underlying vulnerability but said it had already patched the affected application before OneKey published its demonstration.

    Ledger Ethereum flaw broke the trusted display guarantee

    The vulnerability involved communication between a Ledger device and its connected host. Ledger applications receive instructions called Application Protocol Data Unit commands, or APDUs, from wallet software, webpages or other interfaces.

    An affected application could accept a second APDU command while the user was reviewing an earlier operation on the device screen. The new command could overwrite signing parameters stored in shared memory without updating the displayed information.

    Under that scenario, the user could review transaction A and approve it while the application generated a signature covering transaction B. The device would not warn the user that the underlying information had changed.

    Ledger classified the issue as a time-of-check to time-of-use race condition. Its bulletin said the flaw defeated the trusted-display protection that hardware wallets use to let customers verify amounts, addresses and contract actions before signing.

    The issue did not reveal seed phrases or extract private keys from the secure element. Instead, it could cause the protected key to sign parameters different from those shown to the user.

    Exploitation required a compromised connection

    An attacker needed control of communications between the Ledger application and its host. Ledger listed malware, a compromised wallet application, or a hostile webpage with WebHID or WebUSB access as possible routes.

    The attack could not be performed remotely against an unplugged device. A user also had to approve the transaction while the malicious software manipulated its pending signing context.

    Ledger said the defect was located in the input and output handling of its Secure SDK, not the device operating system or firmware. Applications compiled with affected SDK releases depended on their own state checks to reject commands arriving during an active review.

    This means exposure was application-specific. An application remained protected if every asynchronous command entry point properly checked its state, even when built using the affected SDK.

    Ledger disputes whether the test counts as a hack

    Wang described the laboratory result by saying, “we hacked Ledger.” He also said the company fixed the problem in Ethereum app 1.22.3.

    we hacked ledger.

    the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab.

    the bug is a race condition between the transaction display logic and the underlying transaction buffer.

    an attacker can… pic.twitter.com/feT3RnSMh2

    — Yishi (@ohyishi) August 27, 2026

    Ledger Chief Technology Officer Charles Guillemet disputed that description. He said “reproducing an already-patched bug is not ‘hacking Ledger’” and characterized OneKey’s work as a laboratory exercise against an older application.

    The version history supports a more precise timeline. Ethereum app 1.22.2, released Aug. 13, was the first application update containing state checks designed to stop the documented transaction substitution path.

    Ledger then released Secure SDK 26.6.1 on Aug. 21. That update blocks interleaved commands before application code receives them. Applications were subsequently rebuilt using the corrected SDK.

    Ledger now recommends Ethereum app 1.22.3 or later because the newer release contains the broader SDK protection and addresses another transaction-display flaw. OneKey was therefore correct that 1.22.3 is protected, but the first application-level fix appeared in 1.22.2.

    As crypto.news previously reported, Ledger had already said its Ethereum signing vulnerability was fixed before the public disclosure.

    Users must update applications through Ledger Live

    Ledger said it found no evidence that attackers exploited LSB 023 against customers. No cryptocurrency losses have been publicly linked to this specific issue.

    Users should open Ledger Live, install the latest device applications and verify the Ethereum app version on the hardware wallet. Updating firmware alone does not replace applications built with an affected SDK.

    Third-party developers must also review their state handling and rebuild applications with Secure SDK 26.6.1 or later. Ledger said the weakness was introduced in August 2025 and affected SDK versions through 26.6.0.

    The disclosure follows other hardware wallet security fixes. In related coverage, BitBox patched two flaws affecting firmware installation and Bitcoin address handling, also without reporting confirmed exploitation.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleTrump crypto ventures left investors $4.7B underwater: report
    James Wilson

    Related Posts

    Trump crypto ventures left investors $4.7B underwater: report

    August 28, 2026

    Mirae Asset targets $109B digital asset business

    August 28, 2026

    Aave V4 deposits hit record $806M after 30% weekly rise

    August 27, 2026
    Leave A Reply Cancel Reply

    Top Posts

    10 Years of Ethereum | Ethereum Foundation Blog

    June 28, 2026

    Crypto streamer Gainzy nukes his own token 99% with one ‘accidental’ click

    June 28, 2026

    Strategy $12B underwater, STRC cracks: model breaking?

    June 28, 2026

    Pectra Mainnet Announcement | Ethereum Foundation Blog

    June 28, 2026
    Don't Miss

    Ledger rejects hack claim after OneKey recreates bug

    By James WilsonAugust 28, 2026

    Ledger rejected claims that it had been hacked after OneKey’s Anzen security team reproduced a…

    Trump crypto ventures left investors $4.7B underwater: report

    August 28, 2026

    Mirae Asset targets $109B digital asset business

    August 28, 2026

    Aave V4 deposits hit record $806M after 30% weekly rise

    August 27, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    About Us
    About Us

    CryptifyNow: Your daily source for the latest insights, news, and analysis in the ever-evolving world of cryptocurrency.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Ledger rejects hack claim after OneKey recreates bug

    August 28, 2026

    Trump crypto ventures left investors $4.7B underwater: report

    August 28, 2026

    Mirae Asset targets $109B digital asset business

    August 28, 2026
    Lithosphere News Releases
    Copyright © 2026

    Type above and press Enter to search. Press Esc to cancel.