OneKey said it successfully reproduced a transaction replacement attack in a lab environment against an older version of Ledger’s Ethereum app, using a previously patched flaw to overwrite transaction contents during the signing process while a user reviews a legitimate transaction. The issue affected Ledger Ethereum app version 1.22.1.
Ledger released version 1.22.2 on Aug. 13 with application-layer protections and fixed the underlying issue in Secure SDK 26.6.1 on Aug. 21. Ledger said no users were hacked and stressed the incident was only a lab reproduction of a vulnerability in an outdated version. The company added that the flaw was unrelated to mnemonic generation and instead affected transaction handling during signing.
OneKey Reproduces Ledger Transaction Replacement Attack on Older Ethereum App Version
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
