OneKey Team Successfully Replicates Ledger Ethereum App Vulnerability
OneKey founder Yishi Wang said that the company’s Anzen security team successfully reproduced a transaction replacement attack against Ledger Ethereum app version 1.22.1 in a lab. The test showed how a race condition between the display logic and transaction buffer could let an attacker replace a transaction while a user is still reviewing it, making transaction verification the core security concern.
we hacked ledger.
the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab.
the bug is a race condition between the transaction display logic and the underlying transaction buffer.
an attacker can… pic.twitter.com/feT3RnSMh2
- Yishi (@ohyishi) August 27, 2026
According to Wang, the attack depends on compromising the communication path between the Ledger device and its host environment rather than extracting the wallet’s seed phrase. That distinction matters because the flaw affects what the device ultimately signs, meaning a user could approve one transaction on screen while manipulated data is substituted underneath the signing process.
… Continue reading the full article at the original source below.



