Ledger is disputing a rival’s claim that it hacked the company’s hardware wallet, after OneKey’s security team recreated a flaw in an outdated version of Ledger’s Ethereum app and published the result as an attack. Ledger’s response is blunt: the bug was already fixed, no user lost money, and a demonstration against old firmware is not a compromise of current devices.
The dispute turned public within hours of OneKey’s post. According to Ledger’s account, OneKey’s team reproduced what is known as a transaction replacement bug against version 1.22.1 of the Ethereum app, an older release. The flaw, in Ledger’s description, could make the data displayed on a device screen diverge from the data actually signed, which strikes at the core promise of a hardware wallet: what you see is what you approve. If a wallet shows one transaction and signs another, every other protection it offers stops mattering, because the user’s check happens on a screen that is lying.
That is why the claim got attention, and why Ledger’s rebuttal mattered. The company stated that the vulnerability was patched in a later Ethereum app release, that no funds were ever lost to it in the wild, and that the demonstration required deliberately running outdated software. On that reading, OneKey did not hack Ledger. It re-derived a known, fixed bug in a lab and labeled the result in a way Ledger considers misleading. OneKey has continued to stand by its framing, which keeps the argument alive on social media, where most of this fight is happening.
A rivalry shapes the disclosure
The two companies compete directly in the self-custody hardware wallet market, and parts of the crypto community read the disclosure as opportunistic timing rather than neutral research. OneKey has not seriously disputed the core technical facts of the patch timeline; the disagreement is over framing. Calling a reproducible flaw in a rival’s product a hack generates headlines. Calling it a responsibly patched historical bug does not. Ledger, for its part, has responded with enough technical detail, including the specific app version involved, to make its case verifiable by anyone who cares to check.
The episode fits a familiar pattern in security research. Coordinated disclosure gives vendors a window, commonly around 90 days, to ship a fix before details go public. The etiquette assumes the researcher wants the bug dead, not the vendor embarrassed. Publishing a working attack against an already-patched version, without leading with the version number, lets a researcher claim a dramatic result while technically saying nothing false. Ledger’s complaint is essentially about that gap between what is true and what is implied. The company has lived through worse versions of this dynamic before, including the reaction to the wallet.fail presentation years ago, where dramatic-sounding attack paths against Ledger devices turned out to be far less consequential than the framing suggested.
Why display integrity is the line
Hardware wallets sell one guarantee above all others: the device screen shows what is being signed, so a compromised computer cannot swap the recipient or the amount undetected. A display-integrity bug breaks that promise at the root. It does not matter how strong the secure element is, or how carefully keys are protected, if the approval step itself can be deceived. This is the same class of issue that has driven past controversies across the wallet industry, and it is the reason Ledger treated the repro, however stale the firmware, as worth answering publicly rather than ignoring.
The economics of the market sharpen the argument. Hardware wallets are a small category by revenue but a large one by trust, and trust in this business is close to the whole product. Users who hear the word hack attached to a market leader, even wrongly, have alternatives a click away. That is why the fight over one word is not petty. It maps directly to sales, and both companies know it.
For users the practical takeaway is unglamorous. Keep device firmware and coin apps current, because known bugs only bite outdated installs. A flaw in version 1.22.1 of one app says little about the current release, but it says everything about the risk of never updating. Ledger’s bug bounty program, run through its Donjon security team, remains the channel it wants researchers to use, and the company’s message in this dispute was as much about process as about the bug itself: test old versions if you like, but say so clearly.
There is also a competitive wrinkle worth naming. OneKey markets itself on openness and transparency, and security research is one of the few areas where a smaller rival can generate credibility against an incumbent. A credible display-integrity demo against the market leader, even on stale firmware, is worth something commercially. That does not make the research wrong. It does mean readers should weigh the source, the same way they would if Ledger had published a similar attack against OneKey.
Neither company has indicated the dispute will go further than public statements. The underlying flaw is fixed, the demo involved no real users, and the argument is now about words rather than wallets. It still served as a reminder of how thin the margin is in this market. A single ambiguous claim about display integrity can move users between competitors, which is exactly why both sides argued so hard about a bug nobody ever exploited for money.
