Hardware Wallet Security

OneKey Reproduces Transaction Replacement Vulnerability Targeting Outdated Ledger Ethereum App Versions

According to Cointelegraph reporting that is not officially confirmed, hardware wallet competitor OneKey successfully recreated a transaction replacement exploit targeting an older iteration of the Ledger Ethereum application within a controlled laboratory setting.

Conceptual security analysis of hardware wallet transaction signing mechanics
Image: Cointelegraph

Laboratory Replication of the Exploit Vector

Security researchers belonging to the in-house team at open-source hardware wallet provider OneKey recently disclosed that they successfully recreated an attack scenario within a controlled testing environment. According to reporting published by Cointelegraph, the team targeted an outdated iteration of the on-device Ethereum application previously distributed by their industry competitor Ledger. This experimental setup was designed to examine how older firmware versions handle incoming data streams during the crucial transaction signing phase, specifically looking at potential vulnerabilities that might allow unauthorized modifications while the user is actively reviewing the transaction details on the physical screen.

The founder and chief executive officer of OneKey explained to reporters that the reproduced method constitutes a classic transaction replacement attack. By leveraging a previously patched vulnerability present in Ledger Ethereum app version 1.22.1, the simulated malicious setup was theoretically capable of overwriting the pending transaction before final user authorization was granted. The reporting emphasizes that this specific security test was conducted entirely in isolation, utilizing specialized testing equipment rather than targeting active consumer wallets in a live production environment.

Manufacturer Response and Remediation Timeline

In direct response to the public statements released by competing developers, representatives for Ledger issued clarification regarding the nature of the reported lab test. The manufacturer emphasized that successfully executing the described attack vector in a real-world scenario would necessitate extensive prior compromise, including complete control over the communication channels operating between the physical security device and the host machine. Such prerequisites typically involve sophisticated host malware, compromised wallet interface software, or malicious web pages designed to intercept and manipulate local data transmission.

Furthermore, Ledger underscored that the underlying security flaw had already been proactively addressed long before the public laboratory demonstration took place. The organization pointed to the deployment of app-level safeguards introduced in Ethereum application version 1.22.2, which rolled out earlier in August, followed shortly by deeper architectural fixes incorporated within Secure SDK version 26.6.1. Company communications explicitly maintained that no customer assets were ever placed at risk by this specific historical vulnerability, and absolutely no user funds were lost.

Broader Ecosystem Context and Hardware Vulnerabilities

The public discussion surrounding the Ledger application test follows closely behind a series of high-profile security disclosures affecting other prominent self-custody hardware manufacturers across the digital asset industry. Earlier in the summer, independent analysts and researchers highlighted significant vulnerabilities discovered within competing hardware lines, such as firmware bugs that impacted seed phrase generation randomness on certain specialized devices. These recurring security disclosures underscore the intense scrutiny facing hardware wallet manufacturers as they strive to protect complex cryptographic operations against increasingly sophisticated attack vectors.

Industry analysts noted that while seed generation flaws typically threaten the initial creation of private keys, the vulnerability examined by OneKey specifically targets the operational transaction handling mechanics. Because hardware wallets serve as the ultimate line of defense for decentralized finance participants and long-term token holders, any flaw within the signing application interface demands immediate remediation. The ongoing transparency and cross-vendor security testing help drive continuous improvements across the entire hardware security module landscape, benefiting the broader ecosystem.

Technical Analysis of Transaction Signing Mechanics

Examining the mechanics of transaction replacement attacks reveals critical insights into how hardware wallets interact with external software interfaces. When a user initiates a transfer of digital assets, the host application formats the transaction payload and transmits it to the hardware device for explicit verification and cryptographic signing. During this critical window, the device screen must accurately display the intended recipient address, gas parameters, and value to the user, ensuring complete visibility before approval is granted through physical button presses.

The vulnerability addressed in Ledger’s recent updates involved edge cases where insufficient validation of intermediate data states could theoretically allow malicious host software to substitute transaction parameters mid-stream. If an unpatched application failed to properly lock the data buffer during the review process, an attacker with host-level access could alter the transaction destination. The deployment of Secure SDK 26.6.1 and the corresponding Ethereum app patches successfully closed this communication loophole, ensuring that the device firmware strictly validates the immutability of the displayed transaction data until the user confirms the action.

Definitive Findings and Actionable Guidance

Based on the available evidence provided through media reporting from Cointelegraph, the investigation concludes that OneKey successfully replicated an exploit vector targeting outdated Ledger Ethereum applications within a lab environment. However, this reported event remains not officially confirmed by independent third-party forensic audits. The affected entity is Ledger, and the impacted user group consists of individuals utilizing physical hardware wallets who have delayed updating their on-device applications to the latest secure versions. What changes now is that users must actively audit their device firmware versions rather than relying solely on legacy security assumptions.

For the next required action, all participants utilizing self-custody hardware devices must immediately connect their hardware to the official companion software interface and apply all pending firmware updates, specifically ensuring that their Ethereum application is updated to version 1.22.2 or higher. The report distinguishes clearly between the laboratory reproduction demonstrated by researchers and the confirmed absence of actual user fund losses. Readers are advised to maintain rigorous digital hygiene by verifying all device interactions and monitoring official manufacturer channels for future security bulletins.

Cexvia conclusion

Definitive Assessment and Required Mitigation Steps

The investigation establishes that security researchers replicated a historical attack vector affecting unpatched firmware, though Ledger maintains that no user assets were compromised, a claim that remains not officially confirmed by independent audits.

Risk meaning
This development highlights ongoing operational risks associated with delayed firmware updates and external communication channels between hardware devices and host machines.
User action
Users operating physical custody devices should immediately verify application versions and apply the latest available firmware patches provided by the manufacturer.
Ledger