OneKey ‘hacked’ already-patched Ledger app

Crypto wallet maker OneKey and cybersecurity firm Anzen claim to have hacked version 1.22.1 of Ledger’s Ethereum app. Ledger outright disagrees, saying, “No Ledger user was hacked.”
Earlier today, OneKey founder Yishi Wang detailed how his security team reproduced a transaction replacement attack that takes place while a user is reviewing a legitimate transaction.
Wang declared, “We hacked ledger,” and warned users on Ledger’s older Ethereum app to update it, noting that Ledger has already fixed this in version 1.22.3.
Ledger says OneKey didn’t actually hack anything
Ledger’s Chief Technology Officer Charles Guillemet responded hours later, claiming that “reproducing an already-patched bug is not ‘hacking Ledger.’”
He added, “No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding.”
A Ledger spokesperson told Protos that OneKey “took the already disclosed findings and tried to replicate them in a lab environment.”
… Continue reading the full article at the original source below.


