📈 Get daily crypto insights that make you smarter about your money

OneKey Reproduces Transaction Replacement Attack on Outdated Ledger Ethereum App — No User Funds Lost

Open-source hardware wallet provider OneKey has announced that its in-house security team successfully reproduced an exploit targeting an outdated version of Ledger’s on-device Ethereum application in a laboratory environment, renewing attention on how hardware wallets handle the critical moments between transaction review and signing.

OneKey founder and CEO Yishi Wang said the team executed a “transaction replacement attack” against Ledger Ethereum app version 1.22.1 by exploiting a previously patched vulnerability that allows attackers to overwrite the transaction waiting to be signed while the user is still reviewing what they believe is the legitimate transaction on their device screen.

The demonstration matters because it targets the single most important promise of hardware wallets: that what you see on the device display is exactly what gets signed and broadcast to the blockchain. If an attacker can swap the transaction during the review window, that guarantee collapses.

## How the Attack Works

According to OneKey’s disclosure, the exploit requires the attacker to gain control over communications between the Ledger device and its host computer — for example through malware on the machine, compromised wallet software, or a hostile webpage interacting with the device through web-based connectors.

From that position, the attacker can exploit the flaw in the outdated app version to replace the pending transaction with a malicious one, such as redirecting funds to an attacker-controlled address, while the user’s screen still displays the original, legitimate details at the moment of confirmation.

The attack vector is a vivid reminder that hardware wallet security does not live on the device alone. The channel between a computer and a signing device is part of the trust boundary, and a compromised host remains one of the most practical avenues for stealing funds even from well-protected cold storage.

## Ledger’s Response: Patched Before Disclosure

Ledger moved quickly to address the vulnerability, and the timeline is notable. The company said it added app-level safeguards with Ethereum app version 1.22.2, released on August 13, and then fixed the underlying issue more fundamentally in Secure SDK version 26.6.1 on August 21 — both before OneKey’s public demonstration drew attention to the flaw.

The French hardware maker was direct in pushing back against any suggestion that users had been harmed. “No Ledger user was hacked. What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app,” Ledger wrote in a post on X on Thursday.

The company emphasized that exploiting the vulnerability required control over host-to-device communications, meaning everyday users who keep their operating systems clean and only interact with their devices through trusted software faced minimal practical exposure — provided they had updated their Ethereum application after the August patches.

## Echoes of the Coldcard Incident

The disclosure lands in the middle of an unusually active season for hardware wallet security research. In July, attackers exploited a firmware bug introduced in March 2021 that weakened seed randomness on certain Coldcard wallets, leaving the resulting private keys vulnerable to brute-force attacks — one of the most serious hardware wallet failures ever publicly documented.

At the time, Ledger stated that its devices were not affected by the Coldcard vulnerability because recovery phrases on Ledger devices are generated using a certified source of randomness built into the device’s security chip.

OneKey’s newly demonstrated attack is a different class of problem entirely. Rather than compromising seed generation, the transaction replacement technique targets how transactions are handled during the signing process itself — meaning even perfectly generated keys can be misdirected if the signing window is manipulated.

## Practical Lessons for Users

The episode reinforces several long-standing best practices that are too often ignored. First, keeping the on-device applications updated is as important as updating the wallet firmware itself; the vulnerable Ledger Ethereum app had been superseded for weeks before the demonstration became public. Second, users should treat their host computer as hostile territory, since the attack requires no physical access to the device. Third, verifying transaction details on the device screen remains essential, but this case shows that screen verification is only trustworthy when the underlying app is patched.

For the industry, the pattern of security researchers probing market-leading hardware wallets — OneKey probing Ledger after the Coldcard disclosures — suggests a healthier adversarial ecosystem, where vendors police each other’s products and vulnerabilities surface before criminals can industrialize them.

For now, the bottom line for Ledger users is straightforward: update the Ethereum application and Secure SDK, and the demonstrated attack path is closed. No user funds were lost, but the lesson about the space between “what you see” and “what you sign” will linger considerably longer.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

26 thoughts on “OneKey Reproduces Transaction Replacement Attack on Outdated Ledger Ethereum App — No User Funds Lost”

  1. app safeguard lands aug 13, real fix in secure sdk 26.6.1 on aug 21. eight days apart, that gap tells you the first patch was a bandaid

    1. eight days between the shim and secure sdk 26.6.1 is honestly standard practice. at least the real patch shipped the same month, some vendors leave the bandaid as the fix forever

  2. seedsigner_stan

    onekey publishing a full repro of a competitors old bug is messy, but the disclosure pressure is good for users. verify on device or dont sign

    1. Still good that onekey published the repro instead of sitting on it. Full disclosure pushes ledger to nag users harder about updating.

      1. Agreed on disclosure, though publishing a working repro also hands the playbook to anyone still running the old host stack. Double edged.

    2. patched ages ago but half the ledgers i see on trains still run ancient eth apps. the repro existing at all proves the update nag wasnt loud enough

      1. cant even blame the train guys. ledger live pushes the new eth app and half the time its a blind signing toggle scare that makes people abandon the update halfway

      2. the nag was quiet for a reason, restarting the eth app used to break peoples defi signers. folks avoided the update because it cost them a working setup

        1. this is the real adoption blocker nobody counts. every update that resets blind signing settings trains users to defer patches, then a 1.22.1 repro shows why that habit bites

        2. this is the detail security twitter never gets. the 1.22.1 update path had real cost for power users, so the people holding the most were the least likely to ever patch

  3. The scary part is it needs host compromise, so malware on your machine beats your hardware wallet anyway. Clear signing only goes so far.

    1. thats the part nobody wants to hear. your 100 dollar hardware wallet cant save a compromised laptop that hosts the signing session

    2. exactly, the device was never meant to defend against a hostile host. if your usb stack is owned you already lost

      1. hostile host argument only goes so far. the whole point of this bug was the screen showing one tx while the device signed another. thats display integrity, not host trust

  4. the attack needs a compromised host anyway, so no user funds lost tracks. still updating my ledger eth app tonight tho

  5. ledger patched it before disclosure, fine, but a competitor security team demoing it on v1.22.1 is the actual story

    1. The demo was on a version patched months ago, so it is basically marketing with extra steps. Still got a bunch of people to finally hit update, net win.

      1. competitor ships the repro, ledger already patched, users actually update. rare case of rivalry working in our favor

  6. would love to see what percent of devices still sit on 1.22.1. my gut says the number is way higher than anyone at ledger wants to admit

    1. ledger publishes zero stats on app versions so we will never know. my guess, everyone who bought a nano in 2021 and updated exactly once

    2. gut says way higher than ledger admits. go to any meetup and count the devices that havent been plugged in since 2024

    3. ledger publishes device version stats? doubt it. best proxy is still the update nag complaint threads, and those are nowhere near dying down

  7. the repro proves the ugly part of the threat model. your screen shows one tx and the chip signs another, that is a hardware wallet failing at its one job

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$78,035.00+0.0%ETH$2,451.06+0.3%SOL$104.90+0.1%BNB$691.82-0.5%XRP$1.39+0.1%ADA$0.2006-1.3%DOGE$0.0852-0.3%DOT$0.8399-1.6%AVAX$7.30-0.1%LINK$11.42-0.7%UNI$4.62+3.8%ATOM$1.50+1.4%LTC$48.840.0%ARB$0.0880-0.8%NEAR$1.84+1.0%FIL$0.6810-0.5%SUI$0.7435-1.2%BTC$78,035.00+0.0%ETH$2,451.06+0.3%SOL$104.90+0.1%BNB$691.82-0.5%XRP$1.39+0.1%ADA$0.2006-1.3%DOGE$0.0852-0.3%DOT$0.8399-1.6%AVAX$7.30-0.1%LINK$11.42-0.7%UNI$4.62+3.8%ATOM$1.50+1.4%LTC$48.840.0%ARB$0.0880-0.8%NEAR$1.84+1.0%FIL$0.6810-0.5%SUI$0.7435-1.2%
Scroll to Top