OneKey Reproduces Transaction Replacement Attack on Outdated Ledger App
OneKey's in-house security team has successfully reproduced an exploit against an outdated version of Ledger's Ethereum app. The team executed a 'transaction replacement attack' on Ledger Ethereum app 1.22.1, which was fixed by Ledger in its Ethereum app 1.22.2 released on August 13th.
The vulnerability allows attackers to overwrite the transaction waiting to be signed while the user is still reviewing the legitimate transaction. However, this requires control over communications between the device and its host, such as through malware or a hostile webpage.
Ledger had previously said that their devices were not affected by a similar exploit against Coldcard wallets in July because recovery phrases are generated using a certified source of randomness built into the device's security chip. However, the vulnerability reproduced by OneKey is unrelated to seed generation and instead affects how transactions are handled during the signing process.
No Ledger user was compromised as a result of this exploit, and it only occurred in an outdated version of the Ethereum app. The underlying issue was fixed in Secure SDK 26.6.1 on August 21st.