Hardware wallet manufacturer Ledger has responded to a vulnerability in an Ethereum application. The company disclosed that the issue, which has been recently discussed, appeared in the older version Ethereum App 1.22.1. Relevant fixes were deployed before the experimental reproduction results of OneKey were published. Currently, there is no evidence indicating that this vulnerability has been used to attack users in a real-world environment.
On August 27th, Wang Yishi, the founder of OneKey, stated on the X platform that his security team Anzen had reproduced a "transaction replacement" attack in a test environment. According to his description, the vulnerability is related to a race condition between the transaction display logic and the underlying transaction buffer. If an attacker has control over the communication between the device and the host, they may be able to replace the content to be signed while the user is verifying a legitimate transaction.
For a vulnerability to be exploited, it is necessary to first control the communication link.
In the security bulletin issued on the same day, Ledger stated that this issue could result in the device screen displaying one transaction, but in reality, another transaction was signed. However, there are clear prerequisites for such an attack to be successful: the attacker must first gain control of the communication link between the hardware wallet and the computer or mobile phone, either through malware, a compromised wallet application, or by intervening with a malicious website.
The company's Chief Technology Officer, Charles Guillemet, stated that re-running a fixed vulnerability in an older version does not equate to "Ledger being hacked." He mentioned that the company discovered this issue within its internal security processes and had already patched it in the Ethereum App 1.22.2 release on August 13th, which was prior to OneKey making the related tests public.
Fixed in two steps in August.
Ledger reveals that the first step was to launch Ethereum App version 1.22.2 on August 13, which added additional protections. The second step was to fix an underlying issue in Secure SDK version 26.6.1 on August 21, and based on that, to rebuild the related applications accordingly. The company currently recommends that users upgrade to version 1.22.3 or a later version, as this version also fixes another transaction display vulnerability.
- Affected version is Ethereum App 1.22.1
- 1.22.2 released a fix on August 13th.
- Versions 1.22.3 and above are the currently recommended versions.
The company claims to have not seen any evidence of a real attack.
Ledger indicates that, to date, there is no evidence of this vulnerability being exploited outside of the laboratory. Guillemet also states that no users have been attacked by hackers due to this issue. The current information suggests that the related reproductions are part of laboratory tests, and not new attacks in the real world.
The security research team under Ledger also stated on the X platform that this incident highlights the need for hardware wallets to have the capability for software updates. The team noted that it is not uncommon for software vulnerabilities to occur; the key lies in whether manufacturers can quickly push fixes to already sold devices after identifying the issues.
Additional information:Earlier this month, users of Coldcard offline hardware wallets encountered a theft incident involving over $130 million in Bitcoin. Ledger executives stated at the time that this was a warning to the entire hardware wallet industry.











