All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to Crypto & Digital Assets

Ledger Denies Hack Claims, Cites Patched Vulnerability in Ethereum App

Created at 27 Aug · 6:21 PM1 source↑ Market-relevant
IN SHORT

Ledger has refuted claims of a hack, stating that a vulnerability in an outdated version of its Ethereum app was patched before researchers reproduced the exploit. The company urges users to update their apps and firmware.

Key Numbers

1.22.1vulnerable Ethereum app version
August 13date of fix release
1.22.2fixed Ethereum app version
August 21date of Secure SDK fix
26.6.1Secure SDK version
1.22.3recommended Ethereum app version
$130 millionstolen from Coldcard wallets earlier this month

Who's Involved

Ledger
Cryptocurrency wallet developer denying hack claims
OneKey
Rival wallet maker whose researchers reproduced a vulnerability
Yishi Wang
Founder and CEO of OneKey who reported the findings
Charles Guillemet
Ledger Chief Technology Officer refuting hack characterization
Ledger Donjon
Ledger's internal security research team
Ledger Denies Hack Claims, Cites Patched Vulnerability in Ethereum App

↳ Why This Matters

This incident underscores the critical importance of keeping cryptocurrency hardware wallet software updated to protect against known vulnerabilities, even in systems designed for security.

Key facts

  • Ledger denies being hacked, stating a vulnerability in its Ethereum app was patched before a rival firm reproduced it.
  • Researchers at OneKey recreated a transaction-replacement attack on an outdated version (1.22.1) of Ledger's Ethereum app.
  • Ledger's Chief Technology Officer Charles Guillemet stated the flaw was fixed in version 1.22.2, released August 13.
  • Ledger has seen no evidence of attacks against users or exploitation in the wild.
  • The company recommends users update to Ethereum app version 1.22.3 or later and ensure their device firmware is current.

Ledger has refuted claims of a security breach, asserting that a vulnerability identified in an older version of its Ethereum application was addressed and patched before researchers from rival company OneKey publicly demonstrated the exploit. OneKey's security team reported on X that they recreated a transaction-replacement attack against version 1.22.1 of Ledger's Ethereum app in a lab setting. They described the bug as a race condition that could allow an attacker to alter transaction details while a user is reviewing them, potentially redirecting funds. Ledger's Chief Technology Officer, Charles Guillemet, countered that reproducing an already-fixed bug does not constitute a hack, emphasizing that the vulnerability was identified and patched in Ethereum app version 1.22.2, released on August 13, prior to OneKey's publication. Ledger stated that an attacker would need to compromise communications between the device and its host, such as through malware or a hostile website, to exploit the flaw. The company confirmed it has found no evidence of any user being hacked or the vulnerability being exploited in the wild. Ledger subsequently released version 1.22.3 of its Ethereum app, which includes fixes for this issue and a separate transaction-display vulnerability, and recommended users update their apps and device firmware. Ledger's internal security research team, Ledger Donjon, highlighted the importance of updateability in hardware wallets, noting that vulnerabilities can be patched when discovered.

Frequently asked questions

Ledger denies being hacked. They state that a vulnerability in an older version of their Ethereum app was identified and patched before researchers reproduced it in a lab.

The vulnerability was a race condition allowing an attacker to potentially replace transaction details while a user was reviewing a legitimate one, redirecting funds.

Ledger has stated that no users were hacked and there is no evidence of exploitation in the wild.

Ledger recommends users update their device firmware and install the latest version of the Ethereum app (1.22.3 or later) to ensure they are protected.

What Happens Next

01Users are advised to install the latest firmware and apps through Ledger Wallet.
02Users should update the Ethereum app to version 1.22.3 or later.
03Users should verify the app version displayed on their Ledger device.
CME Headlines
  • Bitcoin futures break $80,000 as consumer confidence drops.
    25 Aug · 6:57 PM
  • Bitcoin futures break $80,000 as consumer confidence drops.
    25 Aug · 6:57 PM
  • Can Bitcoin's Long-Term Catalysts Overcome Recent Headwinds?
    24 Aug · 3:00 PM

How It Developed

OneKey reproduced a transaction-replacement attack against Ledger's Ethereum app version 1.22.1.
Ledger's CTO stated the vulnerability was identified and fixed in version 1.22.2 released August 13.
Ledger confirmed no user was hacked and no exploitation in the wild occurred.
Ledger released Ethereum app version 1.22.3, which includes fixes for this and another transaction-display vulnerability.
Ledger advises users to update their firmware and Ethereum app to the latest versions.

Sources

T1
No, Ledger Wasn’t Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company SaysDecrypt

Related Stories

Coldcard Bug Prompts Shift to Multi-Vendor Multisig for Bitcoin Security
26 Aug · 11:46 PM
GoCaracal Malware Uses Ethereum Smart Contract for C2 Access
27 Aug · 1:41 PM
Core Lightning confirms AI-flagged vulnerabilities, urges security update
27 Aug · 8:11 AM
StarkWare tests quantum-resistant Bitcoin transaction on mainnet
27 Aug · 4:25 AM
Bitcoin Wallets Dormant for Over a Decade Move $40M in One Week
26 Aug · 6:51 PM