Official Ledger hardware wallet product lineup supporting Ethereum

Ledger Says Ethereum App Flaw Was Patched Before Researchers Reproduced the Attack

August 27, 2026 3:09 pm Comments

A security team has demonstrated a troubling transaction-replacement attack against an older version of Ledger’s Ethereum app. The important part for users is just as clear: Ledger says the vulnerable version was patched before the demonstration became public, and the company has found no evidence that anyone lost funds through the flaw.

The test was carried out by OneKey’s Anzen security team against Ethereum app version 1.22.1. According to Decrypt’s account of the demonstration, the researchers reproduced a race condition that could let a compromised computer or wallet interface replace transaction data while a user was still reviewing what appeared on a Ledger device.

That distinction matters. The attack was not a remote break-in to every Ledger wallet, and the researchers did not show that Ledger’s hardware had been broadly compromised.

An attacker would first need control over the software communicating with the device—through malware, a hostile website, or a compromised wallet app—and would then try to exploit the timing gap during transaction review.

Here is how OneKey founder Yishi Wang described the lab reproduction:

In practical terms, the danger was a mismatch between the transaction a user believed they were approving and the transaction the device ultimately signed. That cuts directly at the promise of hardware wallets: the device screen is supposed to be the trusted place where a user verifies the final destination and amount before authorizing a transfer.

Ledger says the vulnerable app was already obsolete.

Ledger CTO Charles Guillemet pushed back on the claim that OneKey had “hacked Ledger.” He said the researchers reproduced a bug in an outdated Ethereum app after Ledger had already shipped a correction.

Ledger Donjon’s official security bulletin gives the underlying issue a more precise description. It says the command-handling path could accept new information while an earlier operation was still awaiting the user’s approval.

Because signing data remained in shared state during that review, an affected app could display one set of parameters and sign another.

Ledger says the first application-level guards arrived in Ethereum app version 1.22.2 on August 13. The company then removed the broader command-interleaving opportunity in Secure SDK version 26.6.1 on August 21 and rebuilt affected apps with the corrected software.

The company also says it has no evidence of exploitation against users. That does not make the bug trivial; transaction substitution is exactly the kind of failure hardware wallets are built to prevent.

But the timeline changes the immediate risk: this was a laboratory reproduction against an old app, not evidence of an active mass theft campaign.

What Ledger users should do now.

Ledger’s advice is straightforward: update the Ethereum app to version 1.22.3 or later through Ledger Wallet, keep device firmware and installed apps current, and verify the app version directly on the signer. Firmware and apps update separately, so installing one does not guarantee the other is current.

Users should also keep treating the hardware screen as the final authority. Read the destination, token, amount, and contract details before signing.

If the device cannot clearly display what a transaction will do, rejecting it is safer than trusting the computer or website that prepared it.

The episode is a useful reminder of both sides of hardware-wallet security. A dedicated signing device can isolate keys and expose malicious transaction changes—but only if its software is current and the user actually checks what the trusted screen shows.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.