Ledger Flaw Reproduced in the Lab—But Users on the Current Ethereum App Are Protected

Ledger Flaw Reproduced in the Lab—But Users on the Current Ethereum App Are Protected


Security researcher testing a hardware wallet connected to a laptop in a cyber lab image By Isaac • August 28, 2026 11:06 am •

A hardware-wallet flaw that was already patched has now been reproduced in a lab, giving Ledger users a useful reminder: software updates matter just as much as the device in your hand.

Researchers at OneKey say they successfully carried out a transaction-replacement attack against version 1.22.1 of Ledger’s on-device Ethereum app. The test showed that an attacker who had already compromised communications between the Ledger device and its host computer could replace a transaction while the user was still reviewing what appeared on the device.

Trending: 16-year-old blackmailed middle school teacher over their sexual relationship, Texas police say

Cointelegraph reports that OneKey reproduced the issue in a controlled environment. The important limit is easy to miss: Ledger said exploitation required control over the device-host channel, such as malware, compromised

Continue reading

 

Join the conversation!

Please share your thoughts about this article below. We value your opinions, and would love to see you add to the discussion!