Ledger Denies Hack Claim Amid Vulnerability Reproduction
Cryptocurrency wallet developer Ledger has refuted claims that it was hacked after researchers at rival wallet maker OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger's Ethereum app.
The vulnerability, which affects versions prior to 1.22.2, allows an attacker to show the user a legitimate Ethereum transaction, then replace its details before signing, redirecting funds to the hacker's wallet without the change appearing on the device.
Ledger Chief Technology Officer Charles Guillemet rejected OneKey's characterization of the issue as a hack, stating that reproducing an already-patched bug does not amount to 'hacking Ledger.'
The company found no evidence that anyone exploited the vulnerability outside of a laboratory and emphasized that users were not hacked. It recommends installing the latest firmware and apps through Ledger Wallet, updating the Ethereum app to version 1.22.3 or later.