BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Ledger Disputes Hack Claim After OneKey Recreates Patched Ethereum Flaw

Ledger rejected hack claims after rival OneKey reproduced a transaction-swapping attack on Ethereum(ETH) app 1.22.1, patched two weeks earlier. Key Points: OneKey's Anzen security team recrea

AnonymousCryptoCompass newsroom
August 28, 2026
3 min read
NEWS
Ledger Disputes Hack Claim After OneKey Recreates Patched Ethereum Flaw
CryptoCompass editorial visual for altcoins coverage.

Ledger rejected hack claims after rival OneKey reproduced a transaction-swapping attack on Ethereum(ETH) app 1.22.1, patched two weeks earlier.

Key Points:

  • OneKey's Anzen security team recreated a transaction replacement attack against Ledger's Ethereum app version 1.22.1 in a laboratory.
  • Ledger says the underlying flaw was fixed in Ethereum app 1.22.2 on August 13 and found no sign of exploitation against users.
  • The company now tells customers to install Ethereum app 1.22.3 or later and check the version shown on the device.

Ledger Rejects OneKey Hack Claim

OneKey founder and chief executive Yishi Wangwrote on X on Thursday that the company's Anzen security team had run the attack end to end in a laboratory. He said the bug was a race condition between the transaction display logic and the underlying transaction buffer on the device. His engineers rebuilt the affected app version themselves in order to reproduce the full attack flow.

Ledger described the same condition in a bulletin issued the same day, calling it a race. A device running an affected app could show one set of transaction details on screen while quietly producing a signature that covered entirely different ones.

Also Read:Ethereum Tests Major $2.5K Resistance With Pullback Risk Rising

Charles Guillemet Disputes Exploit Framing

Ledger chief technology officer Charles Guillemet called the demonstration a lab exercise rather than a finding.

He argued that reproducing a bug patched weeks earlier does not amount to hacking the company or its users. Carrying out the attack against a real user would require an adversary already controlling the link between the device and its host, through malware, a compromised wallet app or a hostile webpage. The weakness never exposed seed phrases or private keys held inside the secure chip, and only changed the parameters the device signed.

Ledger found no evidence that anyone had turned the flaw against real customers in the wild, and no stolen funds have been publicly tied to it anywhere. Its Donjon research team said the episode showed why hardware wallets need to support software updates, because a wallet that cannot be patched in the field cannot be repaired at all.

Ledger Ethereum App Patch Timeline

Ledger traced the regression to August 2025 and said it reached every Secure SDK release up to version 26.6.0, which was published on August 11. Application-level guards shipped first, in Ethereum app 1.22.2 on August 13, roughly two weeks before the rival wallet maker's demonstration.

The company then released Secure SDK 26.6.1 on August 21, rebuilt its apps against it and issued the bulletin on August 27, urging users to install version 1.22.3 or later.

The clash lands weeks after attackers began draining Bitcoin(BTC) from Coldcard wallets on Jul. 30, exploiting a firmware flaw dating to March 2021 that weakened how those devices generated their seed phrases. Guillemet called that incident a warning for the whole industry at the time, saying a hardware wallet's security model lives or dies on the quality of its randomness.

Read Next:Can Solana Hold $105? A Closing Validator Vote May Decide