By Isaac • August 27, 2026 3:09 pm •
A security team has demonstrated a troubling transaction-replacement attack against an older version of Ledger’s Ethereum app. The important part for users is just as clear: Ledger says the vulnerable version was patched before the demonstration became public, and the company has found no evidence that anyone lost funds through the flaw.
The test was carried out by OneKey’s Anzen security team against Ethereum app version 1.22.1. According to Decrypt’s account of the demonstration, the researchers reproduced a race condition that could let a compromised computer or wallet interface replace transaction data while a user was still reviewing what appeared on a Ledger device.
Trending: Gratitude is not perspective. It is remembering mercy.
That distinction matters. The attack was not a remote break-in to every
Continue reading
Join the conversation!
Please share your thoughts about this article below. We value your opinions, and would love to see you add to the discussion!