Ledger Denies Hacking Allegations After Vulnerability Patched
Security researchers from OneKey claimed to have recreated an attack on an outdated version of the Ethereum app for Ledger, but Ledger denies hacking allegations. The vulnerability allowed a malicious web application with permissions to connect to the device to send a secondary signing instruction while the user was examining the first. This created a race condition that could replace transactions before signing.
Ledger's Chief Technology Officer, Charles Guillemet, rejected the narrative of a security breach in the manufacturer's infrastructure. The company identified the issue internally and rolled out update 1.22.2 on August 13, 2026. The patch strengthened the system with Secure SDK 26.6.1 on August 21, 2026.
The vulnerability was patched before its public disclosure, and Ledger confirms that no user was hacked. The company published its official security bulletin on August 27, 2026, confirming the absence of active exploits in real-world environments. Users should check their devices for updates to ensure protection.