Ledger Hardware Wallet ‘Hacked’ as OneKey Reveals Transaction-Swapping Flaw

By Giuseppe Ciccomascolo // August 28, 2026 @ 06:57 PM Make AlphaWire Logo preferred on Google News

Share

Ledger Hardware Wallet ‘Hacked’ as OneKey Reveals Transaction-Swapping Flaw

Share

Points of Focus

  • OneKey researchers reproduced a Ledger flaw that could make a device display one Ethereum transaction while signing another.
  • Ledger disputes claims that its hardware wallet was “hacked.”
  • However, Ledger also said there is no evidence of real-world exploitation.

 

 

Ledger is pushing back against claims that its hardware wallet was “hacked” after researchers at rival wallet maker OneKey reproduced a potentially dangerous transaction-swapping vulnerability.

OneKey founder Yishi Wang said on X that the company’s Anzen security team recreated the attack in a laboratory using Ledger’s Ethereum app version 1.22.1.

The vulnerability could theoretically allow malicious software to show users a legitimate transaction on their Ledger screen before replacing the underlying transaction data. The victim could therefore approve transaction A, while the hardware wallet actually signs transaction B.

Ledger acknowledged the underlying security flaw but stressed that it had already patched the affected Ethereum app before OneKey publicly demonstrated the attack.

 

OneKey reproduces Ledger transaction-swapping attack

According to Wang, the vulnerability involved a race condition between Ledger’s transaction display logic and the transaction buffer containing the information waiting to be signed.

Affected applications could continue receiving new APDU commands while users were reviewing transaction details on the device.

 

 

An attacker controlling communications between Ledger and its host could potentially send another command during this period, overwriting the signing parameters without updating the information displayed to the user.

Importantly, the vulnerability did not expose seed phrases or extract private keys. An attacker would also need control over the communication channel through something such as malware, a compromised wallet application, or a malicious website.

 

Ledger says it wasn’t a hardware wallet “hack”

Ledger chief technology officer Charles Guillemet rejected OneKey’s characterization of the demonstration as a successful hack.

Guillemet said it introduced application-level protections in Ethereum app 1.22.2 on Aug. 13, before OneKey’s public demonstration.

 

 

The company subsequently released Secure SDK 26.6.1 on Aug. 21, addressing the underlying issue by preventing interleaved commands from reaching affected applications.

Ledger now recommends Ethereum app 1.22.3 or later, which incorporates broader protection and addresses another transaction-display issue.

 

Ledger users need to update apps

The distinction between app and firmware updates is particularly important for Ledger customers.

Because Ledger traced the vulnerability to “I/O” handling within its Secure SDK and affected applications, simply installing the latest device firmware may not remove the exposure.

 

 

Users should update their Ledger applications through Ledger’s official software and verify that the Ethereum app is running version 1.22.3 or newer.

Ledger said it had found no evidence that attackers exploited the vulnerability in the wild, and no cryptocurrency losses have been publicly linked to the flaw.

Share

Default avatar

Giuseppe Ciccomascolo

After graduating with a Master’s in Advanced Journalism at the London School of Journalism Giuseppe worked as an analyst and Senior Reporter. In 2017, he transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies and played a pivotal role in establishing the academy for a cryptocurrency exchange website.

Table of content

Ad

Related Articles