Crypto news report · source clearly identified

Ledger Confirms Ethereum App Vulnerability Was Patched Before Any Exploit

OneKey showed that an outdated Ledger Ethereum app could sign a transaction different from the one displayed, but Ledger says the flaw was already fixed before any attack could occur.

Security researcher OneKey demonstrated that an older version of Ledger’s Ethereum application could sign a transaction that differed from the one shown on the device’s screen. The demonstration raised concerns that users might be vulnerable to hidden transaction manipulation.

Ledger’s Response

Ledger responded that the vulnerability existed only in an outdated version of the Ethereum app and that the issue had been patched in a prior update. The company emphasized that no known exploit has occurred and that users running the latest app version are protected.

What Users Should Do

Ledger advises all users to ensure their hardware wallet firmware and applications are up to date. Updating the Ethereum app to the latest release eliminates the previously identified signing discrepancy.

Impact on the Ecosystem

The incident highlights the importance of regular software updates for hardware wallets, especially for popular assets like Ethereum (ETH). While no funds were reported lost, the demonstration underscores the need for continuous security audits of wallet firmware and applications.

Source & attribution

News Source

Publisher
Decrypt
Original date
August 27, 2026, 6:16 PM
Original headline
No, Ledger Wasn’t Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says
View original report ↗