Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$86,878▲ 7.12%ETH$2,778▲ 5.38%SOL$118.69▲ 7.70%TOTAL CRYPTO$2.95T▲ 3.67%S&P 5007,764.70▲ 1.18%NASDAQ27,122.09▲ 3.60%DOW52,048.83▼ 2.31%GOLD4,379.10▼ 6.44%WTI91.96▲ 5.63%BRENT96.01▲ 1.72%EUR/USD1.1468▼ 1.88%USD/JPY157.38▼ 0.94%DXY100.42▲ 1.64%
Crypto

Ledger Disputes OneKey Hack Claim Over Patched Wallet Bug

OneKey recreated a transaction-replacement attack on an old Ledger Ethereum app in a lab. Ledger says the flaw was patched in August and no user lost funds.

Pexels – Leeloo The First

OneKey’s security team says it recreated a transaction-replacement attack against Ledger’s Ethereum app in a laboratory, and Ledger fired back the same day that the bug was already patched and no user was ever at risk. The spat between the two rival hardware wallet makers has turned a dry patch note into a public fight over what actually counts as hacking a wallet.

Yishi Wang, founder and CEO of OneKey, said on X on August 27 that his company’s Anzen security team reproduced the attack against Ethereum app version 1.22.1 in a lab. The bug is a race condition between what the device shows on screen and what it actually signs. An attacker who controlled the communication between the wallet and the host computer could show a user a legitimate transaction, swap its details while the user was still reviewing it, and redirect funds without the change ever appearing on the device.

“The bug is a race condition between the transaction display logic and the underlying transaction buffer,” Wang wrote. His team’s post carried a blunter framing: “we hacked ledger.”

How the attack would work

Ledger applications receive instructions from wallet software, web pages and other host interfaces as APDU commands, short for Application Protocol Data Unit. In the affected versions, an app relied on its own state checks to reject commands that arrived in the middle of an active review. If a compromised host pushed a second transaction at the right moment, the user could approve transaction A while the device generated a signature for transaction B. The screen would show no warning that the details underneath had changed.

Ledger classified the flaw as a time-of-check to time-of-use race condition, a well-known class of bug where a system validates something and then acts on it later, leaving a window for the data to change in between. Exposure was application-specific: an app stayed protected if every asynchronous entry point checked its state properly, even when built on the affected software development kit.

Ledger: patch shipped before the claim

Ledger chief technology officer Charles Guillemet rejected the characterization within hours. He said the flaw sat in an outdated version of the Ethereum app and had been fixed in version 1.22.2, released August 13, two weeks before OneKey’s demonstration went public. The company followed with a security bulletin and a deeper fix in Secure SDK 26.6.1 on August 21.

“No user was hacked. No exploitation in the wild,” Guillemet wrote, adding that running an exploit against an old version after the fix shipped is “a lab exercise, not a finding.” Ledger said it found no evidence anyone used the vulnerability outside a laboratory and no losses reported by any user.

The company stressed that exploitation required a specific and serious precondition: control of the channel between the device and the host, through malware, a compromised wallet app, or a hostile website. A thief who has that level of access to a computer is already inside the user’s machine, though the hardware wallet exists precisely to remain trustworthy even then.

Three flaws, different timelines

Ledger’s bulletin actually listed more than one weakness in its Ethereum signing code, tracked as LSB-023 through LSB-025. The table below shows what each did and when the fixes landed.

Issue What it did Fix
LSB-023 Could swap transaction parameters after display, before signing App fix in 1.22.2 (Aug 13), SDK fix in 26.6.1 (Aug 21)
LSB-024 Operation counter wrapped around after 255 operations in a proof of concept Merged May 5, 2026
LSB-025 Could substitute a token approval for an expected payment during swaps Merged May 25, 2026

The timing dispute is the core of the argument. Wang said in his post that Ledger fixed the problem in Ethereum app 1.22.3, a version number that does not match the company’s account. Ledger says 1.22.2 carried the safeguard before OneKey published anything. Either way, both sides agree on the underlying technical point: the device could display one transaction while signing another, and the patch closed that gap.

Why the framing matters

Hardware wallet marketing rests on a simple promise: what you see on the device screen is what gets signed. Any vulnerability in that path strikes at the product’s entire reason for existing, which is why the two companies are arguing about a version number rather than a hypothetical. OneKey benefits from the impression that a competitor’s device was cracked. Ledger benefits from the impression that nothing happened to users. There is also a competitive wrinkle in the background: OneKey sells wallets in the same price range as Ledger’s entry-level devices, and security theatre between direct rivals is a reliable way to win headlines.

“All software has bugs. Hardware wallets are no exception,” Ledger’s internal security research team, Ledger Donjon, wrote in a separate post.

The episode follows a July incident involving a different wallet entirely. Attackers exploited a Coldcard firmware bug introduced in March 2021 that weakened seed randomness on certain models, leaving some private keys open to brute-force attacks. Ledger said at the time that its own devices were unaffected because recovery phrases are generated with a certified randomness source in the secure chip. That incident and this one are unrelated technically. The Coldcard problem affected how keys were created. The Ledger problem affected how transactions were signed, and the two fix categories look nothing alike.

The update lesson

Ledger Donjon drew a practical lesson from the OneKey episode: users should treat firmware and app updates as part of the security model, not an optional extra. A wallet that never updates is a wallet that keeps old bugs forever, and the gap between a patched version and the one a researcher picks to attack is exactly where claims like this one live. The company had already added safeguards in Ethereum app 1.22.2 on August 13, then addressed the root cause in Secure SDK 26.6.1 on August 21, so the SDK-level fix also protects other device applications built on the same code.

For users the bottom line is short. If you run a Ledger with the Ethereum app at 1.22.2 or later, the attack OneKey demonstrated does not work on your setup. If you run something older, update. The race condition was real, the lab reproduction was real, and the disagreement is over whether a two-week-old patch makes the demonstration a warning or a press stunt. Both companies have an incentive to answer that differently, and neither has suggested any user funds were ever in danger from a live attack.

SourcesDecrypt; Cointelegraph; Ledger security bulletin and statements by CTO Charles Guillemet; OneKey statements by CEO Yishi Wang
Share: X