OneKey reproduces transaction-replacement bug in Ledger app

OneKey reproduced a transaction-replacement attack on Ledger’s outdated Ethereum app 1.22.1 in a lab. Ledger says no users lost funds and patched the flaw in 1.22.2 and Secure SDK 26.6.1.
OneKey’s in-house security team recreated a transaction replacement attack against an older on-device Ledger Ethereum app (version 1.22.1) inside a controlled laboratory environment. The test targeted the outdated app and did not involve live users.
OneKey founder Yishi Wang described the technique as a “transaction replacement attack” that leverages a patched vulnerability allowing an attacker to overwrite a pending transaction while a user is still reviewing the legitimate transaction on the device screen.
Ledger wrote on X that the flaw affects only outdated app versions and that exploiting it requires control over communications between the device and its host, for example through malware, compromised wallet software or a hostile webpage.
Ledger added app-level safeguards in Ethereum app 1.22.2, released Aug. 13, and addressed the underlying issue in Secure SDK 26.6.1 on Aug. 21. “No Ledger user was hacked. What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app,” the company wrote.
The reproduced attack occurs during the signing process. While the device displays a legitimate transaction for user review, an attacker with control of the host can replace the pending transaction with a malicious one and have the device sign it.
OneKey presented the reproduction to demonstrate how the earlier flaw could be abused on older app versions. The company reported no user funds were lost in connection with the lab test.
The test follows a separate July incident involving Coldcard hardware wallets, where a firmware bug weakened seed randomness and left some wallets vulnerable to brute-force attacks. Ledger previously stated its devices were not affected by the Coldcard issue because Ledger devices generate recovery phrases using a certified source of randomness built into the device security chip.
The vulnerability reproduced by OneKey is unrelated to seed generation and specifically affects transaction handling during signing. Ledger’s app and SDK updates address the flaw in the older on-device Ethereum application.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.







