Ledger fixes Ethereum signing flaws after OneKey reproduces older bug

OneKey’s lab test hit outdated software, while separate vulnerabilities required another Ledger update
TL;DR
- OneKey reproduced a transaction replacement attack against an outdated Ledger Ethereum app in a controlled environment.
- Ledger said no users were hacked and no in-the-wild exploitation was found for the vulnerabilities discussed.
- Separate signing flaws could hide operations or substitute a token approval for a payment, prompting another Ethereum app update.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Ledger’s Ethereum application contained multiple transaction-signing vulnerabilities that could cause a device to authorize something different from what a user believed they had reviewed, although Ledger said no users were hacked and reported no evidence of exploitation in the wild. OneKey reproduced one already-patched flaw in a laboratory environment, while two separate vulnerabilities remained unresolved until a later Ethereum app release.

OneKey founder and CEO Yishi Wang said the wallet provider’s security team carried out a “transaction replacement attack” against an outdated Ledger Ethereum application. The flaw allowed an attacker controlling communications between the device and its host to replace a transaction waiting to be signed while the user was still reviewing the legitimate transaction on the hardware wallet.
Ledger tracks that vulnerability as LSB-023. The flaw allowed a compromised host to interleave commands so transaction parameters could be changed after appearing on the device but before the signature was produced. Ledger said exploitation required control over communications between the hardware wallet and its host, which could occur through malware, compromised wallet software or a hostile webpage.
Ledger rejected suggestions that OneKey’s test represented a new compromise of current software. “No Ledger user was hacked. What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app,” Ledger wrote. Ledger’s security team separately said it found no evidence of exploitation in the wild.
Ledger Chief Technology Officer Charles Guillemet also rejected characterizing reproduction of an already-patched flaw as “hacking Ledger.” The distinction was central to Ledger’s response because OneKey’s test targeted software that had already been superseded when the demonstration became public.

Two other signing paths remained vulnerable
The earlier application safeguard did not resolve every known Ethereum signing problem. LSB-024 and LSB-025 remained exposed until Ledger released Ethereum app version 1.22.3 on Aug. 25, 2026. The two flaws were disclosed on Aug. 27, making that release or a later version necessary to address the additional signing issues.
LSB-024 affected arrays of operations during clear signing, where transaction details are presented on the hardware wallet for review. Ledger’s proof of concept caused the device to display only the final operation in an attacker-controlled batch even though the resulting signature authorized the entire set, creating a mismatch between what appeared on the device and what was cryptographically approved.
Ledger said exploitation of that flaw required both a compromised host and an unusually large attacker-controlled array. Ledger tested the scenario on a private network fork and reported no losses involving real users.
LSB-025 affected the Exchange application’s token-payment path during swaps. Ledger’s application checked the token, quantity and destination but did not verify that the requested action itself remained a payment. A malicious or compromised swap provider could therefore substitute a token approval using matching parameters and have it signed without an additional device prompt showing that the transaction type had changed.
The approval flaw had specific limits. It could not create an unlimited approval, switch to another token or give permission to an arbitrary address. An approval also did not itself move funds, because another transaction would have been required before approved assets could be transferred. Ledger said it found no evidence that the swap vulnerability had been exploited.
The release history raised a separate issue because the fixes for the two later-disclosed vulnerabilities had already been merged months before the earlier security update reached users. Ledger’s security bulletins did not explain why those corrections were absent from that release, according to the supplied information.
Ledger recommends installing the latest affected Ethereum application through Ledger Live and verifying the installed version directly on the device. Updating hardware-wallet firmware alone does not replace the Ethereum application, meaning the app itself must also be updated.
Ledger defended software updateability as part of its hardware-wallet security model, saying its security team continuously identifies vulnerabilities through internal research and external bug-bounty programs before distributing fixes through software releases.
Signing flaw differs from Coldcard seed-randomness exploit
The Ledger vulnerabilities concerned transaction handling after wallet keys had already been created, rather than seed generation. That distinction separates the case from a Coldcard exploit disclosed in July 2026, where attackers took advantage of a firmware bug introduced in March 2021 that weakened seed randomness on some Coldcard wallets and left resulting private keys vulnerable to brute-force attacks.
Ledger had previously said its devices were not affected by that Coldcard issue because Ledger recovery phrases are generated using a certified source of randomness built into the device’s security chip.
This article has been refined and enhanced by ChatGPT.