Crypto news report · source clearly identified
OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app
OneKey said it reproduced an exploit against an older version of the Ledger app in its lab environment, which Ledger fixed in its Ethereum app 1.22.2, with no user funds lost.

OneKey’s in‑house security team confirmed that it successfully reproduced a transaction replacement attack against an outdated version of Ledger’s on‑device Ethereum application in a controlled test environment.
Attack details
The team targeted Ledger Ethereum app version 1.22.1, exploiting a previously patched vulnerability that allowed an attacker to overwrite a pending transaction while the user was still reviewing the legitimate one.
Ledger’s response
Ledger stated that exploiting the flaw required control over the communication channel between the hardware device and its host, such as through malware, compromised wallet software, or a hostile webpage. The company released Ethereum app version 1.22.2 on August 13, adding app‑level safeguards, and subsequently fixed the underlying issue in Secure SDK 26.6.1 on August 21.
Ledger emphasized that no user funds were lost and that the reproduced exploit involved only an outdated app version.
Context with other hardware wallet issues
The test follows a July exploit of the Coldcard hardware wallet, where a firmware bug introduced in March 2021 weakened seed randomness, making private keys vulnerable to brute‑force attacks. Ledger noted that its devices were not affected by that Coldcard issue because recovery phrases are generated using a certified randomness source within the device’s security chip.
The OneKey‑reproduced vulnerability is unrelated to seed generation; it specifically impacts transaction handling during the signing process.
Source & attribution
News Source
- Publisher
- Cointelegraph
- Original date
- August 28, 2026, 8:21 AM
- Original headline
- OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app