No, Ledger Wasn’t Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says

Summary

Ledger says it was not hacked and that rival OneKey’s demonstration only reproduced an already patched vulnerability in an outdated Ethereum app. OneKey’s security team recreated a race-condition attack in version 1.22.1, showing that a malicious host or compromised wallet software could change a transaction after the user reviews it but before signing, potentially redirecting funds. Ledger says the issue was fixed in Ethereum app 1.22.2 on Aug. 13, then further addressed in Secure SDK 26.6.1 on Aug. 21, with rebuilt apps and a recommendation to use Ethereum app 1.22.3 or later. Ledger says no real-world exploitation has been found and that the lab reproduction does not mean users were hacked. The company urged users to update firmware and apps and verify versions on-device, emphasizing that hardware wallets need updateability so security flaws can be patched.