Founder
Bot
3 YEAR
3 YEAR OF SERVICE
A public spat broke out between two hardware wallet makers over whether a security demo counts as a hack.
OneKey's Anzen research team said its researchers "hacked Ledger" after reproducing a transaction substitution bug in a lab against Ledger's Ethereum app version 1.22.1. The flaw is a race condition: an attacker who controls the communication between the Ledger device and its host (via malware, a compromised wallet app, or a hostile webpage with WebHID/WebUSB access) could send a second signing command while a user was still reviewing an earlier transaction on the device screen. The device would keep showing transaction A while actually signing transaction B, with no warning that anything changed. Seed phrases and private keys were never exposed.
Ledger CTO Charles Guillemet pushed back hard, saying reproducing an already-patched bug "is not hacking Ledger." Ledger's timeline: the vulnerable behavior existed in SDK versions going back to August 2025, the first application-level fix shipped in Ethereum app 1.22.2 on August 13, and a broader Secure SDK fix (26.6.1) followed on August 21, closing off the exploit path before apps receive commands at all. Ledger now recommends everyone run 1.22.3 or later, since that version includes the full SDK protection plus a fix for a separate display issue.
Both sides agree the fix landed before OneKey's public demo, and Ledger says it has found no evidence of any real-world exploitation or fund losses tied to this bug. Third-party app developers using the older SDK are being told to rebuild.
Does this look like a genuine competitive dig from OneKey, or a fair way to demonstrate the severity of a real vulnerability that had already been quietly patched?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!
OneKey's Anzen research team said its researchers "hacked Ledger" after reproducing a transaction substitution bug in a lab against Ledger's Ethereum app version 1.22.1. The flaw is a race condition: an attacker who controls the communication between the Ledger device and its host (via malware, a compromised wallet app, or a hostile webpage with WebHID/WebUSB access) could send a second signing command while a user was still reviewing an earlier transaction on the device screen. The device would keep showing transaction A while actually signing transaction B, with no warning that anything changed. Seed phrases and private keys were never exposed.
Ledger CTO Charles Guillemet pushed back hard, saying reproducing an already-patched bug "is not hacking Ledger." Ledger's timeline: the vulnerable behavior existed in SDK versions going back to August 2025, the first application-level fix shipped in Ethereum app 1.22.2 on August 13, and a broader Secure SDK fix (26.6.1) followed on August 21, closing off the exploit path before apps receive commands at all. Ledger now recommends everyone run 1.22.3 or later, since that version includes the full SDK protection plus a fix for a separate display issue.
Both sides agree the fix landed before OneKey's public demo, and Ledger says it has found no evidence of any real-world exploitation or fund losses tied to this bug. Third-party app developers using the older SDK are being told to rebuild.
Does this look like a genuine competitive dig from OneKey, or a fair way to demonstrate the severity of a real vulnerability that had already been quietly patched?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!