Ledger denied claims that its wallets were hacked. Researchers at OneKey reproduced an old bug in an outdated Ethereum app rather than finding a new flaw in current devices. The episode is a reminder that firmware updates on hardware wallets are not optional.
What actually happened
On August 28, OneKey founder and CEO Yishi Wang wrote on X that the company's Anzen security team reproduced an attack against version 1.22.1 of the Ethereum app on a Ledger device. He said an attacker could swap out a transaction while the user reviews it on screen. The device would display one transfer and sign a different one.
In his writeup, Wang described the flaw as a conflict between the transaction display logic and the buffer that holds data waiting to be signed. He said an attacker could overwrite the pending transaction while the victim was still reviewing the legitimate one on screen.
Ledger responded almost immediately. Chief Technology Officer Charles Guillemet called OneKey's framing misleading. He explained that the flaw sat in an outdated version of the app, one that was already fixed on August 13 in update 1.22.2, before OneKey's post went out.
OneKey, a Taiwanese hardware wallet maker and a direct Ledger competitor, regularly publishes writeups on other vendors' bugs. Each post spreads through the crypto community within minutes, so the wording matters almost as much as the technical finding itself.
How the bug works
The issue is a race condition. It is a mismatch between what the screen shows and what the device actually signs. Malware on a connected computer or phone can swap the transaction data at the last moment. The user sees a familiar address and amount, then approves a transfer to the attacker's wallet instead.
Picture a typical scenario. Someone wants to send 0.5 ETH to an exchange. The device shows the correct recipient address, and they confirm with a button press. But because of the flawed app, the signature ends up on a different transaction, with a swapped address or amount the victim never actually saw on screen.
Pulling this off requires control over the link between the wallet and its host: infected software, a malicious website, or a compromised browser extension. The Ledger chip itself, according to the company, stays secure. Only the data passed to it from outside can be tampered with.
What Ledger says
Guillemet is firm on one point: reproducing an already-patched bug is not the same as hacking Ledger. In a security bulletin published on August 27, the company confirmed the bug could make an app display one transaction while signing another. It found no trace of real-world exploitation outside a lab.
"No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding."
- Charles Guillemet, Chief Technology Officer at Ledger, in a post on X, August 28, 2026
The company laid out a timeline. Safeguards landed in Ethereum app version 1.22.2 on August 13. The root cause was addressed in Secure SDK version 26.6.1 on August 21, after which apps were rebuilt on the patched code. The security bulletin followed on August 27.
Guillemet added that publishing exploit details without mentioning the shipped patch creates a false impression of how big the threat really is. The right approach, in his view, means reporting the flaw and its fix status at the same time.
What wallet owners should do
Ledger recommends updating the Ethereum app to version 1.22.3 or later. That release fixes a separate transaction-display bug as well. Apps and firmware update on different tracks, so both are worth checking.
- Update apps and firmware through the official Ledger Live or Ledger Wallet app.
- Check the Ethereum app version before signing large transfers.
- Verify the recipient address and amount right on the device screen, not just in the browser.
- For comparison, see how update cycles work on Trezor if you are weighing a second hardware wallet.
It is worth watching for phishing too. Scammers often fake urgent update alerts to steal a seed phrase. Ledger never asks for it on a website or inside an app. Updates only come through the official client.
Why this is not a footnote
Ledger's internal research team, Ledger Donjon, made a simple point: a wallet that cannot be updated cannot be fixed either. Regular patches are part of the security design, not a sign something is wrong with the product.
Earlier in August, Coldcard wallet owners lost more than $130 million in Bitcoin to a separate attack. Next to that incident, the OneKey episode looks far less dramatic: no funds were stolen, and the bug was fixed before the public even heard about it. Still, it points to something worth remembering. A hardware wallet protects the keys, not the user's habits.
The hardware wallet market has long outgrown a single brand. Trezor, Tangem, SafePal and others now compete on how fast they respond to researchers' findings, not just on price or design. Episodes like this keep coming up more often this year, and wallet owners are learning to treat these threads as routine security hygiene rather than a red alert. The best habit stays simple: check for updates as regularly as you check your balance.




Comments
Your email address will not be published. Required fields are marked *