Ledger Fixes Vulnerability in Older Ethereum App After OneKey Reproduces Attack
Hardware wallet maker OneKey has identified and recreated a vulnerability in an older version of Ledger's Ethereum app. The flaw, known as a Transaction Replacement Attack, could allow an attacker to swap out a pending transaction with another one while the user is reviewing details on the hardware wallet screen.
This means that the transaction ultimately signed by the user could differ from the original one verified, creating a risk that assets could be sent to an address designated by the attacker. Fortunately, Ledger fixed the issue through Ethereum app version 1.22.2 and Secure SDK 26.6.1 released on August 13 and August 21 respectively.
Ledger has confirmed that no hacking cases have occurred as a result of this vulnerability, which was reproduced in a lab environment by OneKey's security team using the older version 1.22.1 of Ledger's Ethereum app.