Ledger Rejects Hack Claim Over Patched Bug
Ledger has rejected claims that its hardware wallets were hacked after researchers at rival wallet maker OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger’s Ethereum app.
OneKey’s Anzen security team demonstrated the flaw against Ethereum app version 1.22.1 on August 27. Ledger said it had already identified and patched the issue before the demonstration, with no evidence that users were exploited.
Bug Could Alter Transaction Data During Device Approval
The vulnerability involved a race condition between the transaction displayed on a Ledger device and the data ultimately signed.
A compromised host application could send another command while a user was reviewing a legitimate transaction, allowing signing parameters to be altered before approval was completed. That could cause the device to display one transaction while signing altered transaction data.
An attacker would first need control of communications between the Ledger device and its host through malware, a malicious wallet application or a hostile website. The flaw did not expose private keys stored on the device.
OneKey Reproduces Flaw Using Ethereum App 1.22.1
OneKey CEO Yishi Wang said the Anzen team reproduced the full attack flow in a laboratory using Ethereum app 1.22.1.
Ledger disputed the characterization that the demonstration amounted to hacking the company. It said reproducing a known vulnerability against an outdated application showed the flaw was exploitable but did not demonstrate that Ledger systems or customer wallets had been breached.
Ledger traced the underlying issue to command handling in its Secure SDK rather than the device operating system.
Users Should Install Ethereum App 1.22.3 or Later
Ledger added application-level protections in Ethereum app 1.22.2 on August 13, blocking new commands while another operation was awaiting user approval.
The company fixed the underlying command-interleaving behavior in Secure SDK version 26.6.1 on August 21 and released Ethereum app 1.22.3 with additional security fixes on August 25.
Ledger now recommends users install Ethereum app version 1.22.3 or later. Updating device firmware alone is not enough because Ledger applications are updated separately.
Ledger said it has found no evidence that the transaction-replacement flaw was exploited outside security testing.