Market Incident
Public · Developing
No, Ledger Wasn't Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says
OneKey showed how an outdated Ethereum app could sign a transaction different from what a Ledger device displayed. Ledger said this vulnerability was already patched before any exploit occurred, meaning the wallet maker itself was not hacked.
Published:
Updated:
What happened
Security experts at OneKey tested Ledger's Ethereum app and found a flaw that could let a wrong transaction be signed. Ledger responded by saying the flaw was already fixed before the test was made public, and that no real users were affected.
Global impact / market context
This matters because Ledger wallets are used to keep digital money safe. The flaw could have let a scammer trick someone into approving a different payment than what they saw. Since Ledger says it was already patched, the risk for normal users is low, but it shows why keeping software updated is important.
What to watch
- Check if Ledger has released any new software updates for the Ethereum app, because if a fix is already out, users need to install it to stay safe.
- Watch for any reports from Ledger or OneKey about whether the same flaw exists in other wallet apps, since other apps might need similar fixes.
- See if any real-world scams using this flaw are reported, because that would mean the problem was not fully patched and more users could be at risk.
Evidence
- Bitcoin.com — OneKey Anzen Security Team Reproduces Patched Ledger Signing Flaw
- Decrypt — No, Ledger Wasn't Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says
- Protos.com — OneKey hacked already-patched Ledger app
- Incident timeline — OneKey Anzen Security Team Reproduces Patched Ledger Signing Flaw
- Incident timeline — No, Ledger Wasn't Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says
- Incident timeline — OneKey hacked already-patched Ledger app