Security researcher testing a hardware wallet connected to a laptop in a cyber lab

Ledger Flaw Reproduced in the Lab—But Users on the Current Ethereum App Are Protected

August 28, 2026 11:06 am Comments

A hardware-wallet flaw that was already patched has now been reproduced in a lab, giving Ledger users a useful reminder: software updates matter just as much as the device in your hand.

Researchers at OneKey say they successfully carried out a transaction-replacement attack against version 1.22.1 of Ledger’s on-device Ethereum app. The test showed that an attacker who had already compromised communications between the Ledger device and its host computer could replace a transaction while the user was still reviewing what appeared on the device.

Cointelegraph reports that OneKey reproduced the issue in a controlled environment. The important limit is easy to miss: Ledger said exploitation required control over the device-host channel, such as malware, compromised wallet software, or a hostile webpage.

This was not a remote attack against an untouched Ledger sitting offline. The proof instead shows how a compromised host can undermine the transaction-review step users rely on before signing.

OneKey founder Yishi Wang shared the lab result and described a race condition between the transaction display logic and the transaction buffer underneath it.

Ledger’s response is just as important as the proof of concept. The company says Ethereum app 1.22.2 added app-level safeguards on August 13.

It then fixed the underlying issue in Secure SDK 26.6.1 on August 21.

Ledger also stressed that no user was hacked in the episode and that the published demonstration targeted an outdated app version.

The distinction matters. Hardware wallets are designed to keep signing authority away from an internet-connected computer, but users still depend on the device screen and app logic to show the transaction they are actually authorizing.

If that display path and the underlying transaction buffer can fall out of sync, the screen can become a false source of confidence.

That does not mean Ledger owners should panic. It means they should update the Ethereum app and device software, verify they are using trusted wallet software, and treat unexpected transaction details or prompts as a stop sign.

A hardware wallet can sharply reduce risk, but it cannot make a compromised host harmless.

This disclosure is ultimately a positive security story: researchers reproduced a real weakness, the vendor had already shipped app protections, and the deeper SDK repair is now available. The lesson for crypto holders is straightforward—cold storage is strongest when the entire signing stack stays current.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.