PANews|Aug 28, 2026 08:32
[OneKey Reproduces Ledger's Old Version Transaction Replacement Attack, Ledger Claims Vulnerability Fixed with No Users Affected]
According to Cointelegraph, open-source wallet provider OneKey successfully reproduced an attack targeting an older version of Ledger's Ethereum application in a laboratory environment. The attack exploited a previously fixed vulnerability to execute a 'transaction replacement attack,' overwriting the content of a pending transaction while users were reviewing a legitimate transaction. This vulnerability affected version 1.22.1 of the Ledger Ethereum application. Ledger released version 1.22.2 on August 13, adding application-layer protection, and resolved the underlying issue on August 21 with Secure SDK 26.6.1. Ledger emphasized that 'no users were hacked; this was merely a reproduction of the old version vulnerability in a laboratory environment.'
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink