OneKey reproduces Ledger transaction replacement attack in lab
OneKey reproduces transaction replacement attack on an outdated Ledger Ethereum app in a lab test, confirming a patched flaw in version 1.22.1 that let attackers swap the transaction users review before signing. Ledger fixed the issue in Ethereum app 1.22.2 and Secure SDK 26.6.1, and no user funds were lost.
Open-source wallet provider OneKey said its in-house security team successfully replicated the exploit against Ledger Ethereum app 1.22.1 in a test environment. Founder and CEO Yishi Wang said the team executed a transaction replacement attack by exploiting a vulnerability that lets attackers overwrite the transaction waiting to be signed while the user is still reviewing the legitimate one.
The demonstration adds to a string of hardware wallet security reviews this summer. For ongoing coverage of wallet and exchange risks, see our Fintech & Crypto Alerts hub.
Key Takeaways
- OneKey reproduced a transaction replacement attack against Ledger Ethereum app 1.22.1 in a lab environment.
- Ledger patched the flaw in Ethereum app 1.22.2 on Aug. 13 and in Secure SDK 26.6.1 on Aug. 21.
- Exploiting the vulnerability required control over communications between the device and its host.
- Ledger confirmed no user was hacked and no funds were lost.
- The issue is unrelated to seed generation and affects transaction handling during signing.
What Is a Transaction Replacement Attack?
A transaction replacement attack targets the window between when a user initiates a transfer and when they approve it on a hardware wallet. An attacker who controls the communication channel between the device and its host can replace the pending transaction with a different one while the user is still reviewing what they believe is the original request.
In OneKey's lab reproduction, the team exploited this behavior in Ledger Ethereum app 1.22.1. The vulnerability does not affect how recovery phrases or private keys are generated. Instead, it concerns how transactions are handled during the signing process.
How Did OneKey Reproduce the Exploit?
OneKey's security team ran the test internally, not against live user devices. Wang said the team executed the attack by targeting the outdated Ethereum app version that still lacked safeguards added in the subsequent release.
Ledger said exploiting the vulnerability required control over communications between the device and its host. That could come through malware, compromised wallet software, or a hostile webpage intercepting the connection. OneKey's reproduction validated that chain of conditions in a controlled setting.
What Did Ledger Say About the Vulnerability?
Ledger addressed the issue at the app level first, releasing Ethereum app 1.22.2 on Aug. 13. The company then fixed the underlying problem in Secure SDK 26.6.1 on Aug. 21.
In a Thursday post on X, Ledger wrote: "No Ledger user was hacked. What's described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app." The company emphasized that users on current software are protected by the patches already deployed.
Are Ledger Users Still at Risk?
Based on Ledger's statement, no funds were lost and no users were compromised in the wild. The exploit OneKey reproduced depends on an outdated app version plus an attacker controlling the device-host link, a combination that patched software is designed to resist.
The test follows the July Coldcard exploit, when attackers abused a firmware bug from March 2021 that weakened seed randomness on some devices. Ledger had previously said its hardware was not affected by that issue because recovery phrases rely on a certified randomness source built into the security chip. OneKey's finding is a separate class of risk tied to transaction signing, not seed generation.
Reporting on the lab test was first published by Cointelegraph. Users should keep Ledger firmware, the Ethereum app, and connected wallet software updated to benefit from the Aug. 13 and Aug. 21 fixes.