Ledger Disputes OneKey 'Hack' Claim: No User Data Compromised
Crypto wallet maker OneKey and cybersecurity firm Anzen claim to have hacked version 1.22.1 of Ledger's Ethereum app, but Ledger disputes their claims.
According to Yishi Wang, founder of OneKey, his security team was able to reproduce a transaction replacement attack on the older Ethereum app while a user is reviewing a legitimate transaction.
Wang declared that they 'hacked' Ledger and warned users to update their app to version 1.22.3, which has already fixed this issue.
Ledger's Chief Technology Officer Charles Guillemet responded by saying that reproducing an already-patched bug is not 'hacking Ledger.' He added that no user was hacked and that the exploit was only performed in a lab environment after the fix had shipped.