Ledger App Vulnerability Replicated by OneKey Team
The OneKey Team has successfully replicated a vulnerability in the Ledger Ethereum app that was previously patched by the manufacturer.
The team discovered that version 1.22.1 of the app allowed for a race condition that replaced transactions before signing, making it vulnerable to attacks.
Ledger denied claims of hacking and stated that the issue had been patched, but this latest finding raises questions about the severity of the vulnerability and how easily it can be exploited.