Points of Focus
- OneKey researchers reproduced a Ledger flaw that could make a device display one Ethereum transaction while signing another.
- Ledger disputes claims that its hardware wallet was “hacked.”
- However, Ledger also said there is no evidence of real-world exploitation.
Ledger is pushing back against claims that its hardware wallet was “hacked” after researchers at rival wallet maker OneKey reproduced a potentially dangerous transaction-swapping vulnerability.
OneKey founder Yishi Wang said on X that the company’s Anzen security team recreated the attack in a laboratory using Ledger’s Ethereum app version 1.22.1.
The vulnerability could theoretically allow malicious software to show users a legitimate transaction on their Ledger screen before replacing the underlying transaction data. The victim could therefore approve transaction A, while the hardware wallet actually signs transaction B.
Ledger acknowledged the underlying security flaw but stressed that it had already patched the affected Ethereum app before OneKey publicly demonstrated the attack.
OneKey reproduces Ledger transaction-swapping attack
According to Wang, the vulnerability involved a race condition between Ledger’s transaction display logic and the transaction buffer containing the information waiting to be signed.
Affected applications could continue receiving new APDU commands while users were reviewing transaction details on the device.
we hacked ledger.
the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab.
the bug is a race condition between the transaction display logic and the underlying transaction buffer.
an attacker can… pic.twitter.com/feT3RnSMh2
— Yishi (@ohyishi) August 27, 2026
An attacker controlling communications between Ledger and its host could potentially send another command during this period, overwriting the signing parameters without updating the information displayed to the user.
Importantly, the vulnerability did not expose seed phrases or extract private keys. An attacker would also need control over the communication channel through something such as malware, a compromised wallet application, or a malicious website.
Ledger says it wasn’t a hardware wallet “hack”
Ledger chief technology officer Charles Guillemet rejected OneKey’s characterization of the demonstration as a successful hack.
Guillemet said it introduced application-level protections in Ethereum app 1.22.2 on Aug. 13, before OneKey’s public demonstration.
No Ledger user was hacked.
What's described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app.
The issue was already identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post. The…
— Ledger Donjon (@DonjonLedger) August 27, 2026
The company subsequently released Secure SDK 26.6.1 on Aug. 21, addressing the underlying issue by preventing interleaved commands from reaching affected applications.
Ledger now recommends Ethereum app 1.22.3 or later, which incorporates broader protection and addresses another transaction-display issue.
Ledger users need to update apps
The distinction between app and firmware updates is particularly important for Ledger customers.
Because Ledger traced the vulnerability to “I/O” handling within its Secure SDK and affected applications, simply installing the latest device firmware may not remove the exposure.
OneKey's Founder and CEO claims they 'hacked' Ledger.
The vulnerability has already been addressed by Ledger. This is a good reminder to always keep your wallet apps up to date. https://t.co/FjKsGmhubM
— Lark Davis (@LarkDavis) August 28, 2026
Users should update their Ledger applications through Ledger’s official software and verify that the Ethereum app is running version 1.22.3 or newer.
Ledger said it had found no evidence that attackers exploited the vulnerability in the wild, and no cryptocurrency losses have been publicly linked to the flaw.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


