Newsroom
28 August, 2026 / News / AI / Tags: ledger, onekey, sdk, version, device

OneKey security researchers demonstrated a transaction replacement issue in an older Ledger Ethereum application version during laboratory testing, but the hardware wallet maker confirmed the problem was already patched with no funds lost
Hardware wallet manufacturer Ledger has rejected claims that its devices were compromised after rival firm OneKey publicly demonstrated a previously identified vulnerability in an outdated version of its Ethereum application. The open-source wallet provider’s internal team recreated the issue in a controlled lab setting on an older app release, prompting a response from Ledger that emphasized the flaw had been addressed weeks earlier and that no customers suffered losses.
OneKey founder and CEO Yishi Wang reported that the company’s Anzen security researchers successfully carried out what they termed a transaction replacement attack against Ledger’s Ethereum app version 1.22.1. The flaw centers on a race condition involving the transaction display logic and the underlying buffer used for signing.
In the scenario, an attacker with control over the connection between the Ledger device and its host computer could overwrite the details of a pending transaction while the user continued reviewing what appeared on the device screen. The device would then generate a signature for a different set of parameters than those shown, potentially directing funds to an unintended recipient. The display itself would not update to warn the user of the change.
Ledger described the issue as a time-of-check to time-of-use problem that undermined the trusted display feature hardware wallets rely on for verifying transaction details before approval. Importantly, the vulnerability did not allow extraction of private keys or recovery phrases from the secure element. It only affected the parameters that the protected key would sign under specific conditions.
Ledger stated that successful use of the flaw demanded control over communications between the hardware device and the connected host. Possible vectors included malware on the host computer, compromised wallet software, or a hostile webpage that gained access through interfaces such as WebHID or WebUSB. The attack could not occur remotely against a device that was not plugged in, and the user still needed to approve the transaction while the manipulation took place.
The company located the root cause in the input and output handling of its Secure SDK rather than the device operating system or firmware. Applications built with affected SDK versions through 26.6.0 could be exposed if they lacked sufficient state checks for commands arriving during an active review. Applications that properly validated their state remained protected even when compiled with the vulnerable SDK.
Ledger confirmed the existence of the vulnerability but stressed that it had already been resolved before OneKey’s public disclosure. The firm added application-level safeguards in Ethereum app version 1.22.2, released on August 13. It later addressed the underlying issue in Secure SDK version 26.6.1 on August 21 and rebuilt applications with the corrected software.
The company now recommends users install Ethereum app version 1.22.3 or later. That release incorporates the broader SDK protections and also resolves a separate transaction-display issue. Ledger’s security bulletin noted that the weakness originated in August 2025.
Ledger Chief Technology Officer Charles Guillemet rejected characterizations of the demonstration as a successful hack of the company’s products. He noted that reproducing an already-patched issue against an older application version constitutes a laboratory exercise rather than an active breach.
Ledger reported finding no evidence that the vulnerability had been used against any customers or that it had resulted in cryptocurrency losses. The demonstration remained confined to a controlled environment using a superseded application version.
Ledger advised customers to open its companion software, install the latest device applications, and confirm the Ethereum app version directly on the hardware wallet screen. Firmware updates alone do not replace applications that may have been built with an affected SDK. Third-party developers were also encouraged to review their state-handling logic and rebuild applications using Secure SDK 26.6.1 or later.
The episode is unrelated to a separate firmware issue affecting certain Coldcard wallets earlier in the year, which involved weakened seed randomness and left some private keys vulnerable to brute-force attempts. Ledger has previously stated that its devices generate recovery phrases using a certified source of randomness within the security chip and were not affected by that problem.
Ledger’s internal security team, known as Donjon, underscored the value of updateable hardware wallets. The group noted that software can contain bugs and that the ability to deliver patches to devices already in use forms a core element of the company’s security approach.
Users of Ledger devices who have not yet updated their Ethereum application are encouraged to do so promptly through the official software channels to ensure they are running a version that includes the available protections.









