No, Ledger Wasn’t Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says
OneKey demonstrated how an outdated Ethereum app could sign a transaction different from the one shown on a Ledger device, but the wallet maker says the vulnerability had already been fixed.
Jason Nelson
Publisher Decrypt
Aug 27, 2026 at 6:16 PM UTC · 3 phút đọc

Entities
ethereum
Last Updated
39 phút trước
- OneKey reproduced a transaction-replacement attack against version 1.22.1 of Ledger’s Ethereum app.
- Ledger says it fixed the vulnerability in version 1.22.2 before OneKey published its test and has seen no evidence of attacks against users.
- Ledger recommends installing Ethereum app version 1.22.3 or later and checking the app version on the device.
Cryptocurrency wallet developer Ledger rejects claims that it had been hacked after researchers at rival wallet maker OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger’s Ethereum app.
On Thursday, Yishi Wang, founder and CEO of OneKey, said on X that the company’s Anzen security team recreated the attack against Ethereum app version 1.22.1 in a lab.

“The bug is a race condition between the transaction display logic and the underlying transaction buffer,” Wang wrote. “An attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.”
That would mean a hacker who had compromised the software communicating with a vulnerable Ledger app could show the user a legitimate Ethereum transaction, then replace its details before signing, redirecting funds to the hacker’s wallet without the change appearing on the device.
Market Context
Ethereum
ETH
$2,509
+1.57% (24H)
Market Cap
$303.0B
Circulating Supply
120.7M ETH
24H Volume
$16.4B
24H High
$2,565
Article Intelligence
Key Entities
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
