News

Public · Published

OneKey Founder Says Team "Hacked" the Largest Hardware Wallet, Ledger OneKey founder Yishi said the OneKey Anzen team reproduced a transaction-replacement attack on Ledger Ethereum App 1.22.1 in the lab. He said a race condition between display logic and the transaction buffer

OneKey founder Yishi said his team reproduced a transaction-replacement attack on Ledger's Ethereum App version 1.22.1 in a lab. The attack exploits a race condition between the display logic and the transaction buffer, potentially allowing a hacker to replace a transaction shown to the user.

Published:

Updated:

What happened

OneKey founder Yishi said his team reproduced a transaction-replacement attack on Ledger's Ethereum App version 1.22.1 in a lab. The attack exploits a race condition between the display logic and the transaction buffer, potentially allowing a hacker to replace a transaction shown to the user.

Confirmed

Global impact / market context

If real, this could undermine trust in Ledger, the largest hardware wallet maker. Hardware wallets store cryptocurrency keys offline for safety. A flaw that lets attackers swap transactions could put users' funds at risk, affecting Ledger's sales and the broader crypto security market.

Analyst inference

This news may pressure Ledger's reputation and could benefit competitors like OneKey. For Ethereum (ETH) users, the attack targets the app interface, not the blockchain itself. Investor confidence in hardware wallet security is crucial for crypto adoption, so any perceived vulnerability can influence market sentiment.

Analyst inference

What to watch

  1. Ledger's official response to the reported vulnerability, including whether they confirm or deny the attack and if they plan to issue a software update to fix the race condition. Confirmed
  2. Ledger should promptly release a patched version of the Ethereum app and advise users to update. They might also offer a bug bounty to encourage further security research, which would help restore user confidence. Proposed
  3. Watch for any reports of real-world exploits using this method. If attackers have already used it, that could lead to user losses and increased regulatory scrutiny on hardware wallet security standards, affecting the entire industry. Analyst inference

Affected assets

  • ETH — Ethereum

Evidence