Ledger has rejected claims that it was hacked after rival wallet maker OneKey reproduced a transaction-replacement bug in an outdated version of Ledger's Ethereum app. Ledger says it patched the flaw before OneKey published its test and has found no evidence anyone exploited it outside a lab.
Ledger CTO Charles Guillemet pushed back on OneKey after the rival wallet maker said its researchers had recreated a security flaw in Ledger's Ethereum app. Reproducing an already-patched bug, he said, does not amount to hacking the company.
OneKey reproduces a patched flaw
OneKey founder and CEO Yishi Wang said on X that the company's Anzen security team recreated a transaction-replacement attack against version 1.22.1 of Ledger's Ethereum app in a lab. Wang described the bug as a race condition between the transaction display logic and the underlying transaction buffer, which could let an attacker overwrite a transaction awaiting signature while the user still reviews a legitimate one.
Guillemet responded on X, saying the flaw affected an outdated version of the app and that Ledger's own security process had already identified and fixed it in Ethereum app 1.22.2, released Aug. 13, before OneKey's post.
Ledger says no users were affected
In a security bulletin published Thursday, Ledger said the flaw could cause an affected app to display one transaction while signing another, but an attacker would first need to control communications between the device and its host, through malware, a compromised wallet app, or a hostile website. The company said it found no evidence anyone exploited the vulnerability outside a laboratory setting.
According to Guillemet: "No user was hacked. No exploitation in the wild."
Ledger added safeguards in Ethereum app version 1.22.2 on Aug. 13, then fixed the underlying issue in Secure SDK version 26.6.1 on Aug. 21 and rebuilt its apps with the corrected software. The company recommends installing Ethereum app version 1.22.3 or later, which also fixes a separate transaction-display vulnerability, and advises customers to verify the app version shown on their device. Ledger's internal security team, Donjon, said the episode shows why hardware wallets need to support software updates, since a device that cannot be updated cannot be fixed.
The dispute follows an earlier incident this month in which attackers stole more than $130 million in Bitcoin from users of Coldcard air-gapped wallets, which Guillemet had called a warning for the hardware wallet industry.
Source: Decrypt
Trading involves risk.