Ledger Disputes Hacking Claims Amid Vulnerability Disclosure
Security researchers at OneKey claimed to have successfully recreated an attack on Ledger's Ethereum app in a lab setting, sparking controversy. The alleged vulnerability allowed an attacker with control over intermediary software to overwrite transactions while users were reviewing them on screen.
Ledger denied the claims of a security breach and stated that the issue was patched before it was publicly disclosed. According to the company, the problem stemmed from a race condition between the data buffer and the physical device's visual interface in version 1.22.1 of the Ethereum app.
The manufacturer identified the issue internally and rolled out update 1.22.2 on August 13, 2026, followed by an updated Secure SDK to version 26.6.1 on August 21, 2026. Ledger's official security bulletin confirmed that no user was hacked and that the private keys stored in the hardware's secure element were never exposed.
The incident highlights the importance of regular updates for cold wallets, with Ledger advising users to check their devices' protection by verifying they are running version 1.22.3 or higher of the Ethereum app through Ledger Live.