OneKey Reproduces Exploit Against Older Ledger Ethereum App
Security team tests exploit on outdated software
OneKey, an open-source wallet provider, successfully reproduced a security flaw in an older version of the Ledger Ethereum application. The team conducted the test in a controlled lab environment to demonstrate how the vulnerability could be exploited.
Ledger, the hardware wallet company, confirmed that the issue was addressed in its Ethereum app version 1.22.2. The company stated that no user funds were lost and emphasized that the exploit targeted an outdated version of the software.
How the transaction replacement attack works
According to OneKey founder Yishi Wang, the reproduction targeted the Ledger Ethereum app 1.22.1. The attack is a "transaction replacement" that exploits a vulnerability allowing an attacker to overwrite a pending transaction.
This overwriting occurs while the user is still reviewing what they believe to be a legitimate transaction. Essentially, the attacker can swap the transaction waiting to be signed with a different one without the user noticing during the signing process.
Ledger noted that exploiting this vulnerability requires control over the communication between the hardware device and the computer or device it is connected to. This could happen through malware, compromised wallet software, or a malicious website.
Patches released after demonstration
Ledger took action to fix the issue in two stages. The company first released Ethereum app 1.22.2 on August 13, which added safeguards at the application level. Subsequently, on August 21, Ledger addressed the underlying issue in Secure SDK 26.6.1.
In a post on X, Ledger clarified the situation: "No Ledger user was hacked. What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app."
Context regarding recent hardware wallet issues
This incident follows another security event from July involving Coldcard wallets. In that case, attackers exploited a firmware bug introduced in March 2021 that weakened the randomness of seed generation. This weakness left some private keys vulnerable to brute-force attacks.
Ledger had previously stated that its devices were not affected by the Coldcard vulnerability because its recovery phrases are generated using a certified source of randomness built into the device's security chip.
OneKey and Ledger have confirmed that the newly reproduced vulnerability is unrelated to seed generation. Instead, it specifically affects how transactions are handled during the signing process.
Key details confirmed
- OneKey reproduced the exploit in a lab setting, not on live users.
- The vulnerability existed in Ledger Ethereum app 1.22.1 and earlier.
- No Ledger users were hacked or lost funds.
- Ledger patched the issue with app version 1.22.2 and Secure SDK 26.6.1.
- Exploiting the flaw requires control over the connection between the wallet and a host device.