Ledger Denies Hack After Researchers Reproduce Vulnerability
Cryptocurrency wallet developer Ledger has denied claims that it was hacked after researchers at rival wallet maker OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger's Ethereum app.
The vulnerability, which affected Ethereum app version 1.22.1, allowed an attacker to overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one, redirecting funds to the hacker's wallet without the change appearing on the device.
Ledger Chief Technology Officer Charles Guillemet rejected OneKey's characterization, saying that reproducing an already-patched bug does not amount to 'hacking Ledger.'
'What this thread describes is a vulnerability in an outdated version of the Ethereum app,' he wrote. 'It was identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post.'