OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app
Summary
OneKey’s security team reproduced a transaction replacement attack against Ledger’s outdated Ethereum app 1.22.1 in a test setup. The exploit overwrote a pending transaction while the user was still reviewing the legitimate one, using a previously patched flaw. Ledger said this required control of device-host communications, such as via malware, compromised wallet software, or a malicious webpage. It said the issue was mitigated in Ethereum app 1.22.2 on Aug. 13 and fully fixed in Secure SDK 26.6.1 on Aug. 21. Ledger emphasized no users were hacked and that the report covers only a lab reproduction on an outdated version. The flaw affects transaction signing, not seed generation, and is separate from the recent Coldcard weakness.
