Ledger's Ethereum App Flaw Allows Transaction Swap Without User Knowledge
A recent lab test by OneKey's internal security team, Anzen, revealed a vulnerability in Ledger's Ethereum app. The flaw allowed a compromised host to swap the transaction being signed with one that was never shown on the device's screen.
The issue occurred due to a timing gap between two stages of host-to-device commands. A malicious host could send a second command overwriting the transaction buffer, causing the display and signing logic to fall out of sync.
Ledger had already patched this vulnerability in app version 1.22.2, which was released on August 13, 2026. However, OneKey's public demonstration of the flaw came two weeks later, sparking a debate about the trustworthiness of screens in hardware wallets.
According to Ledger, no customer funds were affected by this issue. The company has stated that users who kept their Ethereum app current after August 13 were never exposed to the vulnerable version.