Ledger Denies Hack Claim as Rival OneKey Recreates Ethereum App Bug
A dispute erupted between Ledger and OneKey after the latter's security team recreated a transaction substitution flaw against an outdated version of Ledger's Ethereum app. The bug, which was fixed in app version 1.22.2 released on August 13, allowed a compromised host to swap transaction details after a user approved what they saw on screen.
The attack required control over the connection between the device and host, which could be achieved through malware or a hostile webpage. However, Ledger found no evidence that anyone exploited the flaw or lost funds due to it.
Ledger's Chief Technology Officer Charles Guillemet described OneKey's test as a lab exercise against an outdated app, arguing that reproducing an already patched bug does not amount to hacking the company.