BTCETHBNBSOLXRPUSDCTRXADADOGE
Data by CoinGecko
WalletsBearish

Hardware Wallet Patch Precedes Disclosed Exploit Claim

Hardware wallet manufacturer Ledger has pushed back against assertions that its devices were compromised, following a laboratory demonstration by researchers from rival firm OneKey.

The dispute centers on a transaction-replacement vulnerability in an older version of Ledger’s Ethereum software, which OneKey’s Anzen security team successfully exploited in a controlled environment. However, Ledger maintains the issue had already been resolved before the findings were published.

According to reporting from Crypto.news, OneKey founder Yishi Wang announced on August 27 that his team had completed an attack on the Ledger Ethereum application version 1.22.1. In a public statement regarding the lab test, Wang declared, “we hacked Ledger.”

Ledger Chief Technology Officer Charles Guillemet quickly refuted the characterization of the event as a genuine breach. Guillemet countered that “reproducing an already-patched bug is not ‘hacking Ledger’,” dismissing the demonstration as an exercise against outdated software. A separate report from Decrypt confirmed that Ledger found no evidence of real-world exploitation affecting its user base.

Transaction Substitution Explained

The flaw, formally designated as LSB 023, involved a timing error classified as a time-of-check to time-of-use race condition. Crypto.news detailed that the vulnerability affected the communication between the hardware device and a host interface, such as a wallet application or a webpage.

Hardware Wallet Patch Precedes Disclosed Exploit Claim
According to reporting from Crypto.news, OneKey founder Yishi Wang announced on August 27 that his team had completed an attack on the Ledger Ethereum application version 1.22.1.

During normal operation, a user reviews transaction details on the device’s trusted display before approving. Under the vulnerability, if a compromised host sent a second set of Application Protocol Data Unit (APDU) commands while the first was still under review, the new instructions could quietly overwrite the pending signature parameters in the shared memory without updating the screen.

Consequently, a user might visually confirm one transaction, but the hardware wallet would sign an entirely different set of data. The attack required a compromised host environment, such as malware or a malicious webpage with specific access, and could not be executed remotely against an unplugged device.

Timeline of the Patch

The underlying defect was rooted in the input and output processing of the company's Secure SDK. According to Ledger’s disclosure cited by Crypto.news, the vulnerability was originally introduced in August 2025 and affected SDK releases through version 26.6.0.

Ledger had already initiated software updates to block the exploit path before OneKey publicized its findings. Crypto.news notes that Ledger released Ethereum app 1.22.2 on August 13, which introduced application-level state checks to prevent simultaneous command processing. On August 21, the firm followed up by deploying Secure SDK version 26.6.1, which stops overlapping commands before they can interact with individual applications.

Ledger now advises all users to upgrade to Ethereum application version 1.22.3, which includes the comprehensive SDK protections alongside additional display fixes. To ensure full protection, hardware wallet users must manually update their specific device applications through the Ledger Live interface, as simply updating the core firmware does not automatically patch applications built on earlier SDK iterations.

← All stories