OneKey Reproduces Outdated Ledger Ethereum App Exploit
OneKey's in-house security team has successfully reproduced an exploit targeting Ledger's outdated Ethereum app, version 1.22.1.
The attack, known as a 'transaction replacement' exploit, allowed attackers to overwrite the transaction waiting to be signed while the user is reviewing the legitimate one.
This vulnerability was previously patched in version 1.22.2 of the Ethereum app, released on August 13th, and later fixed at the underlying level in Secure SDK 26.6.1 on August 21st.
Ledger emphasized that no user funds were lost during this exploit, which required control over communications between the device and its host, such as through malware or a compromised wallet software.