OneKey Reproduces Transaction Replacement Attack on Old Version of Ledger
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
OneKey’s security team reproduced a known exploit called a "transaction replacement attack" against an outdated version (1.22.1) of Ledger’s Ethereum app in a lab environment. This vulnerability allowed attackers to overwrite a transaction pending user approval. Ledger fixed this issue in Ethereum app version 1.22.2 and confirmed no user funds were compromised.
Why it matters
The source highlights that while the vulnerability was exploitable in testing, no actual user accounts were affected, emphasizing the importance of timely software updates. No further explanation on broader market or policy impacts is provided.
Key context
The vulnerability required attackers to control the communication between the Ledger device and its host computer, such as via malware or malicious websites. Ledger released app-level safeguards on August 13 and a deeper fix in Secure SDK 26.6.1 on August 21. This incident follows a recent Coldcard wallet exploit but is unrelated to seed generation, instead impacting transaction signing procedures.
Key numbers and entities
OneKey (open-source wallet provider), Ledger (hardware wallet maker), OneKey founder and CEO Yishi Wang, Ethereum app versions 1.22.1 (vulnerable) and 1.22.2 (fixed), Secure SDK 26.6.1. The Coldcard vulnerability was introduced in firmware from March 2021.
What remains unclear
The source does not detail how widespread the use of the outdated app version remains or how quickly users are updating. It also does not specify if any additional protections are planned beyond those already implemented by Ledger.