Close Menu
    Facebook X (Twitter) Instagram
    Facebook Instagram YouTube
    Crypto Go Lore News
    Subscribe
    Saturday, August 29
    • Home
    • Market Analysis
    • Latest
      • Bitcoin News
      • Ethereum News
      • Altcoin News
      • Blockchain News
      • NFT News
      • Market Analysis
      • Mining News
      • Technology
      • Videos
    • Trending Cryptos
    • AI News
    • Market Cap List
    • Mining
    • Trading
    • Contact
    Crypto Go Lore News
    Home»Ethereum»Ledger Denies Hack After OneKey Recreates Ethereum Signing Bug
    Ethereum

    Ledger Denies Hack After OneKey Recreates Ethereum Signing Bug

    CryptoExpertBy CryptoExpertAugust 29, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    Ledger Denies Hack After OneKey Recreates Ethereum Signing Bug
    Share
    Facebook Twitter Pinterest Email Copy Link
    Binance


    TLDR

    OneKey’s security team recreated a transaction substitution flaw against an outdated version of Ledger’s Ethereum app.
    Ledger says it patched the issue with app version 1.22.2 before OneKey went public with its findings.
    The bug let a compromised host swap transaction details after a user approved what they saw on screen.
    An attacker needed control of the connection between the device and host, through malware or a hostile webpage.
    Ledger found no evidence anyone exploited the flaw or lost funds because of it.

    A dispute broke out this week between Ledger and rival hardware wallet maker OneKey over whether a security flaw counted as a real hack. OneKey’s Anzen security team said it reproduced a transaction replacement bug against Ledger’s Ethereum app.

    Ledger pushed back on that framing. The company said the flaw was already fixed in an earlier update before OneKey shared its results.

    OneKey founder Yishi Wang posted on August 27 that his team completed the attack in a lab setting. He said the test targeted Ethereum app version 1.22.1.

    bybit

    Ledger confirmed the bug was real. But the company said app version 1.22.2, released on August 13, already contained fixes for the exact issue OneKey demonstrated.

    How the Vulnerability Worked

    The flaw involved commands sent from a computer or phone to the Ledger device. These commands, called APDUs, tell the device what transaction to sign.

    Under the bug, a second command could arrive while a user was still looking at an earlier transaction on their screen. That new command could quietly change the signing details without updating what the screen showed.

    In practice, a user might approve a transaction they saw on screen while the device actually signed a different one. Ledger called this a race condition between checking data and using it.

    The bug did not expose seed phrases or private keys stored in the secure chip. It only affected what data got signed.

    To pull off the attack, someone needed control over the connection between the app and the host device. Ledger listed malware, a hacked wallet app, or a malicious webpage as possible entry points.

    The attack could not work on a device that wasn’t plugged in or actively signing something. A user still had to approve a transaction while the attack was running in the background.

    Ledger’s Patch Timeline

    Ledger says the underlying weakness was introduced in August 2025. It affected Secure SDK versions used to build the Ethereum app, up through version 26.6.0.

    The company released app version 1.22.2 on August 13 with state checks meant to block the attack. It followed that with Secure SDK 26.6.1 on August 21, which blocks the bad commands at a deeper level before they reach any app.

    we hacked ledger.

    the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab.

    the bug is a race condition between the transaction display logic and the underlying transaction buffer.

    an attacker can… pic.twitter.com/feT3RnSMh2

    — Yishi (@ohyishi) August 27, 2026

    Ledger’s Chief Technology Officer Charles Guillemet said reproducing an already patched bug does not amount to hacking the company. He described OneKey’s test as a lab exercise against an outdated app.

    Ledger now recommends users run Ethereum app 1.22.3 or later. That version includes the newer SDK protections plus a fix for a separate display issue.

    The company said it has not found any evidence the bug was used against real users. No stolen funds have been tied to this issue publicly.

    Ledger is telling users to open Ledger Live, update their device apps, and check their Ethereum app version. It noted that updating device firmware alone does not fix apps built with the older SDK.

    Other wallet makers using the affected SDK were told to review their own code and rebuild with the patched version. The issue is not limited to Ledger’s own apps.

    This story follows a separate case involving rival hardware wallet maker BitBox, which recently patched two unrelated flaws in its firmware installation and Bitcoin address handling. No exploitation was reported in that case either.





    Source link

    Betfury
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    CryptoExpert
    • Website

    Related Posts

    Ethereum

    Ethereum Holders Pull 1.4M ETH Off Exchanges as Price Nears $2,550

    August 28, 2026
    Ethereum

    Analysts Map Out $2,365 and $2,632 Levels

    August 27, 2026
    Ethereum

    Tom Lee Predicts Ethereum Will Lead Tokenization and AI Growth

    August 26, 2026
    Ethereum

    Bitmine ETH Holdings Near 5% as Ether Breaks $2,500

    August 25, 2026
    Ethereum

    Could Ethereum Hit $5,000? On-Chain Data Fuel Bullish Case

    August 24, 2026
    Ethereum

    BTC.TOP Founder Jiang Zhuoer Flips Bullish, Says ETH Could Outperform Bitcoin

    August 23, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Recommended
    Editors Picks

    Ledger Denies Hack After OneKey Recreates Ethereum Signing Bug

    August 29, 2026

    GLM-5.3 Flash Cuts Costs by 17x with Minimal Quality Drop

    August 29, 2026

    Kraken and Galaxy flipped late as Solana approved a major supply cut

    August 29, 2026

    How Bitcoin just proved it could survive a quantum attack

    August 29, 2026
    Latest Posts

    We are a leading platform dedicated to delivering authoritative insights, news, and resources on cryptocurrencies and blockchain technology. At Crypto Go Lore News, our mission is to empower individuals and businesses with reliable, actionable, and up-to-date information about the cryptocurrency ecosystem. We aim to bridge the gap between complex blockchain technology and practical understanding, fostering a more informed global community.

    Latest Posts

    Ledger Denies Hack After OneKey Recreates Ethereum Signing Bug

    August 29, 2026

    GLM-5.3 Flash Cuts Costs by 17x with Minimal Quality Drop

    August 29, 2026

    Kraken and Galaxy flipped late as Solana approved a major supply cut

    August 29, 2026
    Newsletter

    Subscribe to Updates

    Get the latest Crypto news from Crypto Golore News about crypto around the world.

    Facebook Instagram YouTube
    • Contact
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    © 2026 CryptoGoLoreNews. All rights reserved by CryptoGoLoreNews.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 77,650.00
    ethereum
    Ethereum (ETH) $ 2,440.22
    tether
    Tether (USDT) $ 1.00
    bnb
    BNB (BNB) $ 690.03
    xrp
    XRP (XRP) $ 1.38
    usd-coin
    USDC (USDC) $ 0.999976
    solana
    Solana (SOL) $ 103.94
    tron
    TRON (TRX) $ 0.340182
    staked-ether
    Lido Staked Ether (STETH) $ 2,265.05
    figure-heloc
    Figure Heloc (FIGR_HELOC) $ 1.04