Ledger Denies Hack Claim Amid Vulnerability Reproduction
Cryptocurrency wallet developer Ledger has denied claims that it was hacked after researchers at rival wallet maker OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger's Ethereum app.
Yishi Wang, founder and CEO of OneKey, said on X that the company's Anzen security team recreated the attack against Ethereum app version 1.22.1 in a lab.
The vulnerability, which has been patched since August 13, would allow an attacker to display one transaction while signing another, redirecting funds to the hacker's wallet without the change appearing on the device.
However, Ledger Chief Technology Officer Charles Guillemet rejected OneKey's characterization of the issue as a hack, saying that reproducing an already-patched bug does not amount to 'hacking Ledger.'