OneKey Team Successfully Replicates Ledger Ethereum App Vulnerability

NewsFri, 28 Aug 2026 13:59:39 UTC1 hour ago

OneKey founder Yishi Wang said that the company’s Anzen security team successfully reproduced a transaction replacement attack against Ledger Ethereum app version 1.22.1 in a lab. The test showed how a race condition between the display logic and transaction buffer could let an attacker replace a transaction while a user is still reviewing it, making transaction verification the core security concern.

According to Wang, the attack depends on compromising the communication path between the Ledger device and its host environment rather than extracting the wallet’s seed phrase. That distinction matters because the flaw affects what the device ultimately signs, meaning a user could approve one transaction on screen while manipulated data is substituted underneath the signing process.

… Continue reading the full article at the original source below.

Read from Source · crypto-economy.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (crypto-economy.com).

Related