Key facts
- Ledger denies being hacked, stating a vulnerability in its Ethereum app was patched before a rival firm reproduced it.
- Researchers at OneKey recreated a transaction-replacement attack on an outdated version (1.22.1) of Ledger's Ethereum app.
- Ledger's Chief Technology Officer Charles Guillemet stated the flaw was fixed in version 1.22.2, released August 13.
- Ledger has seen no evidence of attacks against users or exploitation in the wild.
- The company recommends users update to Ethereum app version 1.22.3 or later and ensure their device firmware is current.
Ledger has refuted claims of a security breach, asserting that a vulnerability identified in an older version of its Ethereum application was addressed and patched before researchers from rival company OneKey publicly demonstrated the exploit. OneKey's security team reported on X that they recreated a transaction-replacement attack against version 1.22.1 of Ledger's Ethereum app in a lab setting. They described the bug as a race condition that could allow an attacker to alter transaction details while a user is reviewing them, potentially redirecting funds. Ledger's Chief Technology Officer, Charles Guillemet, countered that reproducing an already-fixed bug does not constitute a hack, emphasizing that the vulnerability was identified and patched in Ethereum app version 1.22.2, released on August 13, prior to OneKey's publication. Ledger stated that an attacker would need to compromise communications between the device and its host, such as through malware or a hostile website, to exploit the flaw. The company confirmed it has found no evidence of any user being hacked or the vulnerability being exploited in the wild. Ledger subsequently released version 1.22.3 of its Ethereum app, which includes fixes for this issue and a separate transaction-display vulnerability, and recommended users update their apps and device firmware. Ledger's internal security research team, Ledger Donjon, highlighted the importance of updateability in hardware wallets, noting that vulnerabilities can be patched when discovered.
