Ledger Rejects Hack Claims After OneKey Reproduces Patched Ethereum App Bug

3 min read
Ledger Rejects Hack Claims After OneKey Reproduces Patched Ethereum App Bug
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

Ledger has rejected claims that it was hacked after rival wallet maker OneKey reproduced a transaction-replacement bug in an outdated version of Ledger's Ethereum app. Ledger says it patched the flaw before OneKey published its test and has found no evidence anyone exploited it outside a lab.

Ledger CTO Charles Guillemet pushed back on OneKey after the rival wallet maker said its researchers had recreated a security flaw in Ledger's Ethereum app. Reproducing an already-patched bug, he said, does not amount to hacking the company.

OneKey reproduces a patched flaw

OneKey founder and CEO Yishi Wang said on X that the company's Anzen security team recreated a transaction-replacement attack against version 1.22.1 of Ledger's Ethereum app in a lab. Wang described the bug as a race condition between the transaction display logic and the underlying transaction buffer, which could let an attacker overwrite a transaction awaiting signature while the user still reviews a legitimate one.

Guillemet responded on X, saying the flaw affected an outdated version of the app and that Ledger's own security process had already identified and fixed it in Ethereum app 1.22.2, released Aug. 13, before OneKey's post.

Ledger says no users were affected

In a security bulletin published Thursday, Ledger said the flaw could cause an affected app to display one transaction while signing another, but an attacker would first need to control communications between the device and its host, through malware, a compromised wallet app, or a hostile website. The company said it found no evidence anyone exploited the vulnerability outside a laboratory setting.

According to Guillemet: "No user was hacked. No exploitation in the wild."

Ledger added safeguards in Ethereum app version 1.22.2 on Aug. 13, then fixed the underlying issue in Secure SDK version 26.6.1 on Aug. 21 and rebuilt its apps with the corrected software. The company recommends installing Ethereum app version 1.22.3 or later, which also fixes a separate transaction-display vulnerability, and advises customers to verify the app version shown on their device. Ledger's internal security team, Donjon, said the episode shows why hardware wallets need to support software updates, since a device that cannot be updated cannot be fixed.

The dispute follows an earlier incident this month in which attackers stole more than $130 million in Bitcoin from users of Coldcard air-gapped wallets, which Guillemet had called a warning for the hardware wallet industry.

Source: Decrypt

Trading involves risk.

Most traded markets

BRENT
+2.18% 90.856
BTC / USD
+1.66% 79,958.7
EUR / USD
0% 1.16519
NVDA
+3.35% 226.51
ETH / USD
+0.2% 2,496.80
USD / JPY
-0.02% 159.367
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.