OneKey Reproduces Outdated Ledger Vulnerability in Ethereum App
The open-source wallet provider OneKey has successfully reproduced an exploit targeting an outdated version of Ledger's on-device Ethereum application in a test environment. The vulnerability, which allows attackers to overwrite the transaction waiting to be signed while the user is reviewing the legitimate transaction, was previously patched in August this year.
According to Yishi Wang, founder and CEO of OneKey, they executed a 'transaction replacement attack' against Ledger Ethereum app 1.22.1 by exploiting a vulnerability that lets attackers overwrite the transaction waiting to be signed while the user is still reviewing the legitimate transaction.
Ledger said that exploiting the vulnerability required control over communications between the device and its host, such as through malware, compromised wallet software or a hostile webpage. Ledger added app-level safeguards with Ethereum app 1.22.2 released on Aug. 13, before fixing the underlying issue in Secure SDK 26.6.1 on Aug. 21.
Ledger emphasized that no user was hacked and that this is just a lab reproduction of a vulnerability in an outdated version of the Ethereum app.