Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeNews › OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app
News

OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app

By Priya Chen · · 2 min read

Hardware wallet maker OneKey said it successfully recreated a transaction replacement attack targeting an outdated version of Ledger's Ethereum app, demonstrating a vulnerability that its rival has since patched with no reported loss of user funds.

What OneKey Found

OneKey said it reproduced the exploit inside a controlled lab environment, showing how the flaw could be leveraged against users running an older iteration of Ledger's Ethereum application. The demonstration was intended to illustrate the risks tied to running outdated firmware and applications on hardware wallets.

The attack, described as a transaction replacement technique, could theoretically allow a malicious actor to alter transaction details in ways a user might not detect before signing. Such vulnerabilities strike at the core promise of hardware wallets, which are designed to give users a trusted, tamper-resistant environment for approving crypto transactions.

A hardware wallet is only as safe as the software running on it.

Ledger's Response

Ledger addressed the underlying issue in version 1.22.2 of its Ethereum app, according to OneKey. Importantly, both companies indicated that no user funds were lost as a result of the vulnerability, and the fix means users on the current version are protected.

The episode underscores a recurring theme in the crypto security space: keeping wallet software up to date is a critical line of defense. Even devices marketed on their security credentials can harbor flaws that require prompt patching.

Key takeaways from the disclosure include:

  • The exploit was reproduced only in a lab setting, not in the wild.
  • Ledger has already shipped a fix in Ethereum app version 1.22.2.
  • No user funds were reported lost.

Why It Matters

Competition among hardware wallet providers has intensified, and security research — even when conducted by a direct rival — can benefit the broader ecosystem by prompting faster fixes and greater transparency. For users, the clearest protection remains simple: update to the latest version of any wallet application and firmware as soon as patches become available.

Was this useful?👍 Yes👎 No