OneKey Reproduces Transaction Replacement Attack on Old Version of Ledger Ethereum App
Open-source wallet provider OneKey successfully reproduced a transaction replacement exploit on an outdated version of Ledger's Ethereum app, which Ledger had already patched, confirming no user funds were lost.
Intelligence analysis by Gemini 2.5 Flash

OneKey's security team demonstrated a transaction replacement attack against Ledger Ethereum app 1.22.1 in a lab setting. This vulnerability, which allowed attackers to swap a legitimate transaction with a malicious one during user review, was previously fixed by Ledger in app version 1.22.2 and later in Secure SDK 26.6.1, ensuring no actual Ledger users were affected.
Imagine you're playing a video game where you need to press 'OK' to buy a new sword. A sneaky trickster could quickly swap the sword picture for a picture of a silly hat right before you press 'OK,' making you buy the wrong thing! Luckily, the game makers found this trick and fixed it before anyone lost their cool swords, and another smart game company showed how the trick worked to make sure it was really fixed.
Analysis
The recent reproduction of a transaction replacement attack by OneKey's in-house security team against an older version of Ledger's Ethereum application serves as a crucial reminder of the ongoing cat-and-mouse game in cryptocurrency security. While Ledger had already addressed the vulnerability, OneKey's successful replication in a controlled lab environment validates the severity of the original flaw and the effectiveness of Ledger's subsequent patches. This collaborative, albeit retrospective, security research contributes significantly to the overall robustness of the hardware wallet ecosystem, fostering greater trust and transparency among users.
OneKey
OneKey, an open-source wallet provider, played a pivotal role in this security disclosure by actively reproducing the exploit. Their founder and CEO, Yishi Wang, publicly detailed the 'transaction replacement attack,' demonstrating how a malicious actor could overwrite a legitimate transaction awaiting user signature. This proactive approach by an industry peer not only verifies the existence and nature of the vulnerability but also reinforces the importance of community-driven security audits. By sharing their findings, OneKey contributes to a culture of continuous improvement and vigilance within the crypto hardware space, benefiting all users.
Ledger Ethereum app 1.22.1
The specific target of OneKey's reproduction was Ledger Ethereum app 1.22.1, an older iteration of the software running on Ledger devices. The vulnerability within this version allowed for a critical 'transaction replacement attack,' where an attacker, having control over the communication channel between the Ledger device and its host (e.g., via malware or a compromised webpage), could swap out the transaction details displayed to the user for review with a different, malicious transaction. This meant a user might approve what they believed to be a legitimate transfer, only to unknowingly sign off on an entirely different, potentially fraudulent, operation. The exploit highlighted a significant risk to user funds if not addressed.
Secure SDK 26.6.1
Ledger's response to this vulnerability was multi-layered and timely, as noted in the article. They first implemented app-level safeguards with the release of Ethereum app 1.22.2 on August 13, effectively mitigating the immediate threat. Subsequently, a more fundamental fix was deployed in Secure SDK 26.6.1 on August 21, addressing the underlying issue at a deeper level within the device's software development kit. This two-step patching process demonstrates Ledger's commitment to security, first by providing an immediate protective layer and then by resolving the root cause. The fact that no Ledger user was hacked underscores the effectiveness of their rapid response and the importance of users keeping their device software updated.
Key points
- OneKey reproduced a 'transaction replacement attack' on Ledger Ethereum app 1.22.1 in a lab environment.
- The exploit allowed attackers to overwrite a transaction waiting to be signed while the user was reviewing the legitimate one.
- Ledger had already fixed this vulnerability in Ethereum app 1.22.2 (Aug 13) and Secure SDK 26.6.1 (Aug 21).
- No Ledger user funds were lost due to this specific vulnerability.
- The attack required control over communications between the Ledger device and its host, such as through malware.
The successful reproduction of the exploit by OneKey, coupled with Ledger's prior and effective patching, demonstrates a robust security ecosystem where vulnerabilities are identified and addressed. This proactive approach by hardware wallet providers and security researchers helps to continuously strengthen the defenses protecting user funds.
Despite the fix, the existence of such a vulnerability, even in an outdated version, highlights the constant threat landscape for hardware wallets. If users fail to update their devices promptly, they could remain exposed to similar sophisticated attacks, underscoring the critical need for user vigilance and timely software maintenance.



