OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app
OneKey said it reproduced an exploit against an older version of the Ledger app in its lab environment, which Ledger fixed in its Ethereum app 1.22.2, with no user funds lost. The in-house security team at open-source wallet provider OneKey said it successfully reproduced an exploit targeting an outdated version of Ledger’s on-device Ethereum application in a test environment.

Why It Matters
This story touches on ledger, app, onekey — topics readers are actively tracking. Review and add editorial context before publishing.
Key Facts
- Fact 1: OneKey said it reproduced an exploit against an older version of the Ledger app in its lab environment, which Ledger fixed in its Ethereum app 1.22.2, with no user funds lost.
- Fact 2: OneKey founder and CEO Yishi Wang said they executed a “transaction replacement attack” against Ledger Ethereum app 1.22.1 by exploiting a previously patched vulnerability that lets attackers overwrite the transaction waiting to be signed while the user is still reviewing the legitimate transaction.
- Fact 3: Ledger added app-level safeguards with Ethereum app 1.22.2 released on Aug.
- Fact 4: 13, before fixing the underlying issue in Secure SDK 26.6.1 on Aug.
OneKey said it reproduced an exploit against an older version of the Ledger app in its lab environment, which Ledger fixed in its Ethereum app 1.22.2, with no user funds lost. The in-house security team at open-source wallet provider OneKey said it successfully reproduced an exploit targeting an outdated version of Ledger’s on-device Ethereum application in a test environment.
OneKey founder and CEO Yishi Wang said they executed a “transaction replacement attack” against Ledger Ethereum app 1.22.1 by exploiting a previously patched vulnerability that lets attackers overwrite the transaction waiting to be signed while the user is still reviewing the legitimate transaction. Ledger said exploiting the vulnerability required control over communications between the device and its host, such as through malware, compromised wallet software or a hostile webpage. Ledger added app-level safeguards with Ethereum app 1.22.2 released on Aug.
(Original synthesis pending human/AI review — generated by the stub provider by selecting real sentences from the source material, not by writing new analysis or commentary.)
Keep Reading

London Stock Exchange to work with Payward to bring biggest UK stocks onchain

Live updates: Bitcoin ETFs resume buying as ether funds stretch streak to 11 days

Strategy spends $635M buying back STRC as perpetual preferred stock lags $100 par
