Ledger Rejects 'Hack' Claim as OneKey Reproduces Flaw
Ledger has rejected claims that it was hacked after OneKey's Anzen security team successfully recreated a transaction replacement flaw against an outdated version of Ledger's Ethereum application.
The vulnerability, which affected Ethereum app version 1.22.1, allowed an attacker to manipulate the user's pending signing context without updating the displayed information.
Ledger confirmed that the underlying issue was fixed in version 1.22.2, released on August 13, and further patched with Secure SDK 26.6.1 on August 21.
OneKey founder Yishi Wang described the laboratory result as 'we hacked Ledger,' but Ledger's Chief Technology Officer Charles Guillemet disputed that description, calling it a 'laboratory exercise against an older application.'