Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$81,258▲ 4.21%ETH$2,639▲ 5.68%SOL$111.61▲ 5.72%TOTAL CRYPTO$2.8T▲ 1.22%S&P 5007,650.50▼ 0.54%NASDAQ26,522.55▲ 0.89%DOW51,682.64▼ 3.11%GOLD4,424.90▲ 0.10%WTI96.08▲ 13.12%BRENT99.29▲ 9.09%EUR/USD1.1490▼ 0.80%USD/JPY156.86▼ 1.56%DXY100.22▲ 0.57%
Crypto

Ledger Rejects OneKey Hack Claim Over Patched Bug

OneKey reproduced a transaction-swap attack on an old Ledger Ethereum app. Ledger says the bug was fixed on Aug. 13 and no user was ever hacked.

Pexels – Leeloo The First

OneKey’s security team said this week it had “hacked” a Ledger hardware wallet in a laboratory. Ledger pushed back hard: the bug was real, but it was patched two weeks before the demonstration, and the company says no user was ever at risk.

On Aug. 27, OneKey founder and chief executive Yishi Wang posted on X that his firm’s Anzen security team had reproduced a “transaction replacement attack” against version 1.22.1 of Ledger’s on-device Ethereum application. His engineers rebuilt the old app themselves to run the full attack flow from start to finish, and published the result as a successful compromise.

“The bug is a race condition between the transaction display logic and the underlying transaction buffer,” Wang wrote. “An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.”

In practice, the flaw meant a device could show one set of transaction details on its screen while producing a signature that covered entirely different ones. A user approving a transfer to a known address might actually be signing a payment to an attacker’s wallet, with nothing on the device screen to suggest the switch. An attacker would first need control of the link between the wallet and the computer or phone it is plugged into, through malware, a compromised wallet app or a hostile webpage. The bug never exposed seed phrases or the private keys stored in the secure chip. It changed what the device signed, not what it protected.

The weak point sits in how the device takes instructions. Ledger apps receive commands called APDUs, short for Application Protocol Data Unit, from wallet software, browsers or other host programs. The patched SDK now blocks interleaved commands before application code sees them, closing the window that let a compromised host slip a second transaction in behind the first.

A patch that beat the demo

Ledger tracks the flaw as LSB-023 and says its own security process caught it first. The company shipped app-level safeguards in Ethereum app 1.22.2 on Aug. 13, then fixed the underlying problem in Secure SDK 26.6.1 on Aug. 21. Apps were rebuilt against the corrected SDK, and the security bulletin describing the race condition went out on Aug. 27, the same day as OneKey’s post.

Chief technology officer Charles Guillemet rejected the framing outright. “Reproducing an already-patched bug is not ‘hacking Ledger’,” he wrote. “No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding.”

Ledger’s internal research group, Donjon, took a softer line in a separate post. “All software has bugs. Hardware wallets are no exception,” the team wrote, adding that the episode shows why a hardware wallet must support software updates, because a device that cannot be patched in the field cannot be repaired at all. The team also noted that OneKey was right about one detail: version 1.22.3 is fully protected, though the first application-level fix actually landed in 1.22.2.

Two more bugs surfaced

Reporting on the exchange turned up two additional flaws in the same Ethereum app, both already fixed before any public demonstration. LSB-024 involved a counting error during clear signing, the mode where transaction details are presented on the device for review. The app read an operation count as a 16-bit value but stored the running total in an 8-bit field, so a 257-operation batch exceeded the smaller field’s 255-value capacity and wrapped the count back to one. Ledger’s records show the fix was merged on May 5. LSB-025 affected the token-payment path in the Exchange application used for swaps and could substitute a token approval for an expected payment. That correction was merged on May 25.

Why the timing matters

The dispute lands weeks after attackers began draining bitcoin from Coldcard wallets in July, exploiting a firmware bug introduced in March 2021 that weakened seed randomness on some devices. More than $130 million was reported stolen in that episode, and the resulting private keys were vulnerable to brute-force attacks. Ledger said at the time that its devices were unaffected because recovery phrases are generated from a certified randomness source in the security chip.

The two incidents are unrelated technically. The Coldcard flaw touched seed generation. The Ledger bug OneKey demonstrated affects only how transactions are handled during signing. But together they have put hardware wallet security back at the center of conversation in a market where users hold more value on self-custody devices than at any point in the last cycle, and where rival vendors now openly test each other’s products for weaknesses.

For users the practical advice is short. Update the Ethereum app to version 1.22.3 or later through Ledger Live, and check the version shown on the device screen. Firmware and apps update separately, so both need attention. Beyond that, Ledger’s own guidance repeats an old truth of wallet security: this class of exploit requires a compromised host computer, so keeping the machine that talks to the wallet clean matters as much as the device itself. The company reports no evidence that anyone exploited LSB-023 outside a laboratory, and no crypto losses have been publicly linked to it anywhere.

Both sides agree on the underlying facts. The bug existed, it was serious in principle, and it is gone from current software. What they disagree on is whether calling it a hack was fair. On the evidence published so far, Ledger’s version holds: a patched flaw, demonstrated against superseded software, with no victims.

Share: X