Crypto news report · source clearly identified

OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app

OneKey said it reproduced an exploit against an older version of the Ledger app in its lab environment, which Ledger fixed in its Ethereum app 1.22.2, with no user funds lost.

OneKey’s in‑house security team confirmed that it successfully reproduced a transaction replacement attack against an outdated version of Ledger’s on‑device Ethereum application in a controlled test environment.

Attack details

The team targeted Ledger Ethereum app version 1.22.1, exploiting a previously patched vulnerability that allowed an attacker to overwrite a pending transaction while the user was still reviewing the legitimate one.

Ledger’s response

Ledger stated that exploiting the flaw required control over the communication channel between the hardware device and its host, such as through malware, compromised wallet software, or a hostile webpage. The company released Ethereum app version 1.22.2 on August 13, adding app‑level safeguards, and subsequently fixed the underlying issue in Secure SDK 26.6.1 on August 21.

Ledger emphasized that no user funds were lost and that the reproduced exploit involved only an outdated app version.

Context with other hardware wallet issues

The test follows a July exploit of the Coldcard hardware wallet, where a firmware bug introduced in March 2021 weakened seed randomness, making private keys vulnerable to brute‑force attacks. Ledger noted that its devices were not affected by that Coldcard issue because recovery phrases are generated using a certified randomness source within the device’s security chip.

The OneKey‑reproduced vulnerability is unrelated to seed generation; it specifically impacts transaction handling during the signing process.

Source & attribution

News Source

Publisher
Cointelegraph
Original date
August 28, 2026, 8:21 AM
Original headline
OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app
View original report ↗