Ledger Disputes OneKey's Hacking Claim on Ethereum App
Ledger, a hardware wallet company, is disputing claims that its Ethereum app was hacked by rival OneKey. The alleged hack used a transaction-swapping attack on Ethereum (ETH) app version 1.22.1, which was patched two weeks earlier.
According to Ledger's chief technology officer Charles Guillemet, reproducing the bug in a laboratory does not amount to hacking the company or its users. He argued that carrying out the attack against a real user would require an adversary already controlling the link between the device and its host, through malware, a compromised wallet app, or a hostile webpage.
Ledger found no evidence that anyone had turned the flaw against real customers in the wild, and no stolen funds have been publicly tied to it anywhere. The company's Donjon research team said the episode showed why hardware wallets need to support software updates, because a wallet that cannot be patched in the field cannot be repaired at all.
Ledger traced the regression to August 2025 and released Secure SDK 26.6.1 on August 21, rebuilt its apps against it, and issued a bulletin urging users to install version 1.22.3 or later.