Ledger Disputes OneKey Hack Claim After Flaw Reproduction
OneKey's Anzen security team successfully recreated a transaction replacement flaw in Ledger's Ethereum app version 1.22.1, but Ledger disputes that this constitutes a 'hack.'
The vulnerability allowed an attacker to manipulate pending transactions by sending malicious APDU commands between the device and its host.
However, Ledger claims that the issue was already patched in version 1.22.2, released on August 13, which added state checks to prevent the attack.
Charles Guillemet, Ledger's Chief Technology Officer, stated that reproducing an already-patched bug is not 'hacking' and that OneKey's work was simply a laboratory exercise against an older application.