cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Ledger fixes Ethereum signing flaws after OneKey reproduces older bug

Ledger fixes Ethereum signing flaws after OneKey reproduces older bug

Van Thanh Le

Van Thanh Le

PublishedAug 29 2026

UpdatedAug 29 2026

3 hours ago4 minutes read
Ledger robot analyzing Ethereum app vulnerabilities in security lab

OneKey’s lab test hit outdated software, while separate vulnerabilities required another Ledger update

TL;DR

  • OneKey reproduced a transaction replacement attack against an outdated Ledger Ethereum app in a controlled environment.
  • Ledger said no users were hacked and no in-the-wild exploitation was found for the vulnerabilities discussed.
  • Separate signing flaws could hide operations or substitute a token approval for a payment, prompting another Ethereum app update.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


Ledger’s Ethereum application contained multiple transaction-signing vulnerabilities that could cause a device to authorize something different from what a user believed they had reviewed, although Ledger said no users were hacked and reported no evidence of exploitation in the wild. OneKey reproduced one already-patched flaw in a laboratory environment, while two separate vulnerabilities remained unresolved until a later Ethereum app release.

tweet-2092982673757122857.webp

OneKey founder and CEO Yishi Wang said the wallet provider’s security team carried out a “transaction replacement attack” against an outdated Ledger Ethereum application. The flaw allowed an attacker controlling communications between the device and its host to replace a transaction waiting to be signed while the user was still reviewing the legitimate transaction on the hardware wallet.

Ledger tracks that vulnerability as LSB-023. The flaw allowed a compromised host to interleave commands so transaction parameters could be changed after appearing on the device but before the signature was produced. Ledger said exploitation required control over communications between the hardware wallet and its host, which could occur through malware, compromised wallet software or a hostile webpage.

Issue Technical effect Patch history
LSB-023 Could alter transaction parameters after display but before signing; OneKey reproduced it against Ethereum app 1.22.1. Ledger added app-level safeguards in Ethereum app 1.22.2 on Aug. 13, 2026, then fixed the underlying issue in Secure SDK 26.6.1 on Aug. 21, eight days later.
LSB-024 The app read an operation count with a 16-bit value but stored the remaining count in an 8-bit field. A 257-operation proof of concept exceeded the smaller field’s 255-value capacity and wrapped the count back to one. Ledger records showed the correction was merged on May 5, 2026.
LSB-025 Affected the token-payment path used by Ledger’s Exchange application during swaps and could substitute a token approval for an expected payment. Ledger records showed the swap-validation correction was merged on May 25, 2026.

Ledger rejected suggestions that OneKey’s test represented a new compromise of current software. “No Ledger user was hacked. What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app,” Ledger wrote. Ledger’s security team separately said it found no evidence of exploitation in the wild.

Ledger Chief Technology Officer Charles Guillemet also rejected characterizing reproduction of an already-patched flaw as “hacking Ledger.” The distinction was central to Ledger’s response because OneKey’s test targeted software that had already been superseded when the demonstration became public.

tweet-2092988392477016321.webp

Two other signing paths remained vulnerable

The earlier application safeguard did not resolve every known Ethereum signing problem. LSB-024 and LSB-025 remained exposed until Ledger released Ethereum app version 1.22.3 on Aug. 25, 2026. The two flaws were disclosed on Aug. 27, making that release or a later version necessary to address the additional signing issues.

LSB-024 affected arrays of operations during clear signing, where transaction details are presented on the hardware wallet for review. Ledger’s proof of concept caused the device to display only the final operation in an attacker-controlled batch even though the resulting signature authorized the entire set, creating a mismatch between what appeared on the device and what was cryptographically approved.

Ledger said exploitation of that flaw required both a compromised host and an unusually large attacker-controlled array. Ledger tested the scenario on a private network fork and reported no losses involving real users.

LSB-025 affected the Exchange application’s token-payment path during swaps. Ledger’s application checked the token, quantity and destination but did not verify that the requested action itself remained a payment. A malicious or compromised swap provider could therefore substitute a token approval using matching parameters and have it signed without an additional device prompt showing that the transaction type had changed.

The approval flaw had specific limits. It could not create an unlimited approval, switch to another token or give permission to an arbitrary address. An approval also did not itself move funds, because another transaction would have been required before approved assets could be transferred. Ledger said it found no evidence that the swap vulnerability had been exploited.

The release history raised a separate issue because the fixes for the two later-disclosed vulnerabilities had already been merged months before the earlier security update reached users. Ledger’s security bulletins did not explain why those corrections were absent from that release, according to the supplied information.

Ledger recommends installing the latest affected Ethereum application through Ledger Live and verifying the installed version directly on the device. Updating hardware-wallet firmware alone does not replace the Ethereum application, meaning the app itself must also be updated.

Ledger defended software updateability as part of its hardware-wallet security model, saying its security team continuously identifies vulnerabilities through internal research and external bug-bounty programs before distributing fixes through software releases.

Signing flaw differs from Coldcard seed-randomness exploit

The Ledger vulnerabilities concerned transaction handling after wallet keys had already been created, rather than seed generation. That distinction separates the case from a Coldcard exploit disclosed in July 2026, where attackers took advantage of a firmware bug introduced in March 2021 that weakened seed randomness on some Coldcard wallets and left resulting private keys vulnerable to brute-force attacks.

Ledger had previously said its devices were not affected by that Coldcard issue because Ledger recovery phrases are generated using a certified source of randomness built into the device’s security chip.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.14.15
© 2017 - 2026 COIN360.com. All Rights Reserved.