Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

OneKey reproduced a fixed Ethereum app flaw in a lab and called it a hack. Ledger says it patched the bug two weeks earlier.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
August 28, 2026
in Security & Hacks
0 0
Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

Image by Pete Linforth from Pixabay/Edited by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Ledger says none of its users were hacked, after hardware wallet rival OneKey said its security team had reproduced a “transaction replacement” attack against Ledger’s Ethereum app, on August 27. Ledger’s security research unit, Donjon, confirmed the underlying flaw in  a bulletin published the same day. The bug let an attacker overwrite a transaction waiting for a signature while the wallet owner was still reviewing a different, legitimate one, a timing flaw between the screen showing the transaction and the buffer actually signing it.

we hacked ledger.

the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab.

the bug is a race condition between the transaction display logic and the underlying transaction buffer.

an attacker can… pic.twitter.com/feT3RnSMh2

— Yishi (@ohyishi) August 27, 2026

Ledger says it already closed that gap. The Ethereum app itself was patched on August 13, and the underlying Secure SDK was patched on August 21, roughly two weeks before OneKey’s post. The bulletin states plainly that Ledger has no evidence the bug was exploited against any user. The bug was not something a remote attacker could pull off on its own. TestMachine’s own writeup described the precondition as a malicious dApp with WebHID access racing a command into the device during the review screen, meaning the wallet had to already be connected to a compromised or malicious site or application for the swap to happen.

Ledger has faced this kind of dispute before without it holding up. In June, a user reported losing 2.3 million ADA from a Ledger wallet without signing anything, a claim that was never backed by public on-chain evidence.

Ledger Ethereum Ap
Ledger Ethereum Ap

OneKey’s demonstration was not the first time this fixed bug resurfaced publicly. Security firm TestMachine described a matching issue around August 21 to 23, days after Ledger’s SDK patch and before OneKey’s post. We covered that earlier round of the dispute when Ledger had not yet published a public bulletin for it, and when affected models spanned the Nano X, Nano S Plus, Stax, Apex and Flex lines. Both disclosures landed on a version of the software Ledger had already retired.

Ledger’s CTO, Charles Guillemet, has pushed back directly on both outside disclosures, saying the flaw was actually found first by Ledger’s own Donjon team through AI-assisted vulnerability research, and criticizing TestMachine for going public without properly coordinating with Ledger once a fix already existed.

Ledger used the same day as OneKey’s post to publish two further bulletins covering unrelated signing flows: a clear-signing bypass affecting Ethereum app versions 1.19.0 through 1.22.2, and a swap-flow issue affecting versions 1.20.0 through 1.22.2 that could accept a token approval in place of a payment. Both were fixed in version 1.22.3, and neither bulletin lists any confirmed loss.

Ledger is advising users to update to 1.22.3 or later on both firmware and the Ethereum app through Ledger Live, and to check the app version on the device screen itself, since the two update separately. We have reached out to OneKey for comment and haven’t received any reply.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: crypto security
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows
Security & Hacks

Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

by Saravana Kumar Mahendran
August 27, 2026

Crypto platforms that had already passed independent security audits still accounted for 88.44% of the $3.63 billion stolen in hacks...

Read moreDetails
Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

August 27, 2026
Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

August 20, 2026
Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

August 19, 2026
BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

August 18, 2026
Ravencoin’s Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team

Ravencoin’s Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team

August 11, 2026
Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

August 7, 2026
Next Post
Abu Dhabi Sheikh's Investment Vehicle Holds 49% of Trump Family's New Crypto Bank

Abu Dhabi Sheikh's Investment Vehicle Holds 49% of Trump Family's New Crypto Bank

Trump earned $1.4 billion from crypto ventures that left investors $4.7 billion underwater

Trump’s Crypto Ventures Put Investors $4.7 Billion Underwater, Public Citizen Says

Recommended

  • All
  • Crypto News Today
Abu Dhabi Sheikh's Investment Vehicle Holds 49% of Trump Family's New Crypto Bank

Abu Dhabi Sheikh’s Investment Vehicle Holds 49% of Trump Family’s New Crypto Bank

August 28, 2026
Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

August 28, 2026
Ripple Prime Launches Delta One, Opening Total Return Swaps on US Stocks

Ripple Prime Expands Into US Stock Trading With Delta One Launch

August 27, 2026 - Updated on August 28, 2026
Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

August 27, 2026
UK Writes Bank of England's Stablecoin Softening Into Law With New Innovation Duty

UK Writes Bank of England’s Stablecoin Softening Into Law With New Innovation Duty

August 27, 2026
Bitfinex Securities Raises Record $50M for Nickel-Backed ALKN Tokens

Bitfinex Securities Raises Record $50M for Nickel-Backed ALKN Tokens

August 27, 2026
Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

August 27, 2026
Pump.fun Leads Hyperliquid in Daily and Monthly Revenue. Hyperliquid's Own Fee Rules Are Why

Pump.fun Leads Hyperliquid in Daily and Monthly Revenue. Hyperliquid’s Own Fee Rules Are Why

August 27, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Trump’s Crypto Ventures Put Investors $4.7 Billion Underwater, Public Citizen Says
  • Abu Dhabi Sheikh’s Investment Vehicle Holds 49% of Trump Family’s New Crypto Bank
  • Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.