Ledger Denies Hack After OneKey Demonstrates Vulnerability
Ledger has denied that it was hacked after OneKey's security team recreated a transaction substitution flaw in an outdated version of Ledger's Ethereum app.
The vulnerability, which affected Secure SDK versions used to build the Ethereum app up through version 26.6.0, allowed an attacker with control over the connection between the device and host to swap transaction details after a user approved what they saw on screen.
Ledger says it patched the issue in app version 1.22.2, released on August 13, before OneKey went public with its findings.
The bug did not expose seed phrases or private keys stored in the secure chip and only affected what data got signed.