discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

OneKey Reproduces Transaction Replacement Attack on Old Version of Ledger Ethereum App

Open-source wallet provider OneKey successfully reproduced a transaction replacement exploit on an outdated version of Ledger's Ethereum app, which Ledger had already patched, confirming no user funds were lost.

By Zoltan Vardai·Aug 28·cointelegraph.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

OneKey Reproduces Transaction Replacement Attack on Old Version of Ledger Ethereum App
Image: cointelegraph.com

OneKey's security team demonstrated a transaction replacement attack against Ledger Ethereum app 1.22.1 in a lab setting. This vulnerability, which allowed attackers to swap a legitimate transaction with a malicious one during user review, was previously fixed by Ledger in app version 1.22.2 and later in Secure SDK 26.6.1, ensuring no actual Ledger users were affected.

Why it matters

This incident highlights the critical importance of promptly updating hardware wallet firmware and applications to protect against sophisticated exploits. It also underscores the value of independent security research by firms like OneKey in validating and improving the security posture of widely used crypto hardware.

Imagine you're playing a video game where you need to press 'OK' to buy a new sword. A sneaky trickster could quickly swap the sword picture for a picture of a silly hat right before you press 'OK,' making you buy the wrong thing! Luckily, the game makers found this trick and fixed it before anyone lost their cool swords, and another smart game company showed how the trick worked to make sure it was really fixed.

Analysis

The recent reproduction of a transaction replacement attack by OneKey's in-house security team against an older version of Ledger's Ethereum application serves as a crucial reminder of the ongoing cat-and-mouse game in cryptocurrency security. While Ledger had already addressed the vulnerability, OneKey's successful replication in a controlled lab environment validates the severity of the original flaw and the effectiveness of Ledger's subsequent patches. This collaborative, albeit retrospective, security research contributes significantly to the overall robustness of the hardware wallet ecosystem, fostering greater trust and transparency among users.

OneKey

OneKey, an open-source wallet provider, played a pivotal role in this security disclosure by actively reproducing the exploit. Their founder and CEO, Yishi Wang, publicly detailed the 'transaction replacement attack,' demonstrating how a malicious actor could overwrite a legitimate transaction awaiting user signature. This proactive approach by an industry peer not only verifies the existence and nature of the vulnerability but also reinforces the importance of community-driven security audits. By sharing their findings, OneKey contributes to a culture of continuous improvement and vigilance within the crypto hardware space, benefiting all users.

Ledger Ethereum app 1.22.1

The specific target of OneKey's reproduction was Ledger Ethereum app 1.22.1, an older iteration of the software running on Ledger devices. The vulnerability within this version allowed for a critical 'transaction replacement attack,' where an attacker, having control over the communication channel between the Ledger device and its host (e.g., via malware or a compromised webpage), could swap out the transaction details displayed to the user for review with a different, malicious transaction. This meant a user might approve what they believed to be a legitimate transfer, only to unknowingly sign off on an entirely different, potentially fraudulent, operation. The exploit highlighted a significant risk to user funds if not addressed.

Secure SDK 26.6.1

Ledger's response to this vulnerability was multi-layered and timely, as noted in the article. They first implemented app-level safeguards with the release of Ethereum app 1.22.2 on August 13, effectively mitigating the immediate threat. Subsequently, a more fundamental fix was deployed in Secure SDK 26.6.1 on August 21, addressing the underlying issue at a deeper level within the device's software development kit. This two-step patching process demonstrates Ledger's commitment to security, first by providing an immediate protective layer and then by resolving the root cause. The fact that no Ledger user was hacked underscores the effectiveness of their rapid response and the importance of users keeping their device software updated.

Key points

  • OneKey reproduced a 'transaction replacement attack' on Ledger Ethereum app 1.22.1 in a lab environment.
  • The exploit allowed attackers to overwrite a transaction waiting to be signed while the user was reviewing the legitimate one.
  • Ledger had already fixed this vulnerability in Ethereum app 1.22.2 (Aug 13) and Secure SDK 26.6.1 (Aug 21).
  • No Ledger user funds were lost due to this specific vulnerability.
  • The attack required control over communications between the Ledger device and its host, such as through malware.
The Upside

The successful reproduction of the exploit by OneKey, coupled with Ledger's prior and effective patching, demonstrates a robust security ecosystem where vulnerabilities are identified and addressed. This proactive approach by hardware wallet providers and security researchers helps to continuously strengthen the defenses protecting user funds.

The Downside

Despite the fix, the existence of such a vulnerability, even in an outdated version, highlights the constant threat landscape for hardware wallets. If users fail to update their devices promptly, they could remain exposed to similar sophisticated attacks, underscoring the critical need for user vigilance and timely software maintenance.

Originally reported at

cointelegraph.com

Discernion covers the story. Read the full piece at the source.

Tagscryptosecurityhardware-walletvulnerabilityethereumcybersecurity

Author

Zoltan Vardai

Intelligence analysis by

Gemini 2.5 Flash

Published

Aug 28, 2026

Source

cointelegraph.com

Share

Topics

cryptosecurityhardware-walletvulnerabilityethereumcybersecurity

Related

More from this desk

Aug 28·cointelegraph.com

Visa works with Upbit parent on stablecoin payments, AI commerce

Visa and Dunamu, the parent company of South Korean crypto exchange Upbit, have partnered to explore stablecoin payments, cross-border remittances, and AI-powered commerce. The collaboration aims to integrate digital assets with traditional finance through Visa's global n…

quantum computing bitcoin StarkWare Quantum Safe Bitcoin QSB
Aug 27·decrypt.co

Bitcoin Completes First Experimental Quantum-Safe Transaction, Starkware Says

Starkware announced the first experimental quantum-safe Bitcoin transaction was successfully mined on the mainnet, utilizing a method that protects against future quantum attacks without altering Bitcoin's core consensus rules.

Aug 27·cointelegraph.com

Virtu, Tradeweb complete onchain repo using Marshall Islands digital bond

Virtu, Tradeweb and M1X Global completed an onchain repo transaction using a sovereign digital bond as collateral. The full transaction settled on the Canton Network in under 10 minutes.

Aug 27·cointelegraph.com

Trump Cost Investors $4.7B Through Crypto 'Schemes': Public Citizen

Public Citizen reports Trump left investors at least $4.7 billion underwater through his crypto ventures.