OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app

OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app
Spread the love

Written by Zoltan Vardaistaff writerReviewed by Yohan Yunstaff editor

Written by Zoltan Vardaistaff writer

Reviewed by Yohan Yunstaff editor

OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app

Latest NewsPublishedAug 28, 2026

OneKey stated it reproduced an exploit against an older version of the Ledger app in its lab environment, which Ledger fixed in its Ethereum app 1.22.2, with no user funds lost.

The in-house security team at open-source wallet provider OneKey stated it successfully reproduced an exploit targeting an outdated version of Ledger’s on-device Ethereum application in a test environment.

OneKey founder and CEO Yishi Wang stated they executed a “transaction replacement attack” against Ledger Ethereum app 1.22.1 by exploiting a previously patched vulnerability that lets attackers overwrite the transaction waiting to be signed while the user is still reviewing the legitimate transaction.

Ledger stated exploiting the vulnerability required control over communications between the device and its host, such as through malware, compromised wallet software or a hostile webpage. Ledger added app-level safeguards with Ethereum app 1.22.2 released on Aug. 13, before fixing the underlying issue in Secure SDK 26.6.1 on Aug. 21.

“No Ledger user was hacked. What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app,” Ledger wrote in a Thursday X post. 

The security test follows the Coldcard exploit in July, when attackers exploited a firmware bug introduced in March 2021 that weakened seed randomness on some Coldcard wallets, leaving the resulting private keys vulnerable to brute-force attacks.

Ledger had previously stated its devices were not affected by the Coldcard vulnerability because recovery phrases are generated using a certified source of randomness built into the device’s security chip.

The vulnerability reproduced by OneKey is unrelated to seed generation and instead affects how transactions are handled during the signing process.

Magazine: Inside the ‘fake police raid’ that forced a $1M Bitcoin transfer

1 minute letter

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

  • Ledger
  • Hardware Wallet
  • Hacks
  • Cybersecurity
  • Self Custody
  • Scams & Cybercrime

More on the subject

Chainalysis-led operation flags 7,700 accounts in child abuse probe



Aug 25, 2026

Ezra Reguerra

Business owner faces up to 280 years over $24M crypto Ponzi scheme



Aug 25, 2026

Ezra Reguerra

Coldcard strengthens seed generation with firmware update



Aug 21, 2026

Zoltan Vardai

Chainalysis-led operation flags 7,700 accounts in child abuse probe



Aug 25, 2026

Ezra Reguerra

Business owner faces up to 280 years over $24M crypto Ponzi scheme



Aug 25, 2026

Ezra Reguerra

Coldcard strengthens seed generation with firmware update



Aug 21, 2026

Zoltan Vardai


💡 A Greener Way to Earn: Looking for a smarter, more sustainable way to earn and mining crypto? EcoPool Network is a cloud-based mining pool that does the heavy lifting on remote servers — so you earn rewards around the clock without worrying about overheating hardware or sky-high electricity bills. It’s lightweight, battery-friendly, and built for everyday users. Download EcoPool now and start mining & earning smarter today.

Spread the love

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these