OneKey Busted: Ledger Disputes Hacking Claims Amid Update Warning
OneKey, a cybersecurity firm, claims to have successfully hacked an already-patched version of Ledger's Ethereum app. The hack, which was said to have been reproduced by OneKey's security team, is a transaction replacement attack that occurs while a user reviews a legitimate transaction.
According to OneKey founder Yishi Wang, the hack 'takes place while a user is reviewing a legitimate transaction.' However, Ledger disputes these claims, stating that no users were actually hacked and that the alleged hack was simply a lab exercise reproducing an already-patched bug.
Ledger's Chief Technology Officer Charles Guillemet responded by saying, 'No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding.'
OneKey warned users on Ledger's older Ethereum app to update it, as Ledger had already fixed this issue in version 1.22.3.