Ledger Rejects Hacking Claims After Rival Wallet Maker Reproduces Vulnerability
Cryptocurrency wallet developer Ledger has pushed back against claims from rival wallet maker OneKey that it had been hacked after researchers at OneKey reproduced a transaction-replacement vulnerability using an outdated version of Ledger's Ethereum app.
According to Yishi Wang, founder and CEO of OneKey, the company's Anzen security team recreated the attack against Ethereum app version 1.22.1 in a lab. The bug is a race condition between the transaction display logic and the underlying transaction buffer, allowing an attacker to overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.
Ledger Chief Technology Officer Charles Guillemet rejected OneKey's characterization, saying that reproducing an already-patched bug does not amount to 'hacking Ledger.' He noted that the flaw was identified through Ledger's security process and fixed in Ethereum app 1.22.2 on August 13, before OneKey published its test.
Ledger added safeguards in Ethereum app version 1.22.2 on Aug 13, then addressed the underlying issue in Secure SDK version 26.6.1 on Aug 21 and rebuilt its apps with the corrected software. The company recommends version 1.22.3 or later, which also fixes a separate transaction-display vulnerability.