๐Ÿ“… Thursday, 3 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
OneKey Klaim Bobol Keamanan Ledger - Tapi Celah Substitusi Transaksi Ternyata Sudah Ditambal Dua Minggu Lalu

OneKey Claims Ledger Security Breach - But Transaction Substitution Flaw Was Already Patched Two Weeks Ago

OneKey founder Yishi Wang announced on August 27 that his Anzen security team reproduced a transaction replacement attack against Ledger devices in a laboratory setting. The primary target was version 1.22.1 of Ledger’s Ethereum application.

The issue centered around instruction stacking. Affected Ledger apps could receive a second APDU command while the user was still reviewing the first operation on-screen. Consequently, signing parameters in shared memory were overwritten immediately without triggering an update on the visual display. Users believed they were approving transaction A, whereas the digital signature output by the device actually authorized transaction B. Ledger classified this vulnerability as a “time-of-check to time-of-use” race condition.

Fixes Preceding the Announcement

Ledger CTO Charles Guillemet responded firmly to the claim, stressing that reproducing an already-patched bug does not constitute hacking Ledger devices.

In fact, the transaction substitution path had been cut off two weeks before OneKey’s announcement. Ledger rolled out the Ethereum app version 1.22.2 update on August 13, introducing initial status checks to halt overlapping attacks. This defense was further reinforced on August 21 with the release of Secure SDK 26.6.1. The updated system blocks conflicting commands before instructions reach application-level code.

Ledger now advises all users to update their Ethereum app to version 1.22.3 or later. This latest version includes broader SDK protections while resolving a separate transaction display flaw.

Secure Element Remains Uncompromised

Although the software vulnerability introduced since August 2025 affected SDK versions up to 26.6.0, the core security element of the device was never compromised. No seed phrases were exposed and no private keys were extracted from the secure element. This race condition flaw also strictly relied on manipulating an active device and does not enable remote access to a hardware wallet disconnected from a computer.

Ledger stated there is no indication that hackers exploited this vulnerability, designated LSB 023, against customers. To date, no cryptocurrency losses have been linked to this specific issue. While security lab findings remain valuable, Ledger’s defensive fixes arrived well ahead of any real-world risks.

Reported by crypto.news.

Read also: Kraken Hit by 12,000 Crypto Dust Transfers - European Sanctions Rules Turn Into a Weapon


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share