Ledger says none of its users were hacked, after hardware wallet rival OneKey said its security team had reproduced a “transaction replacement” attack against Ledger’s Ethereum app, on August
Ledger says none of its users were hacked, after hardware wallet rival OneKey said its security team had reproduced a “transaction replacement” attack against Ledger’s Ethereum app, on August 27. Ledger’s security research unit, Donjon, confirmed the underlying flaw in a bulletin published the same day. The bug let an attacker overwrite a transaction waiting for a signature while the wallet owner was still reviewing a different, legitimate one, a timing flaw between the screen showing the transaction and the buffer actually signing it.
Ledger says it already closed that gap. The Ethereum app itself was patched on August 13, and the underlying Secure SDK was patched on August 21, roughly two weeks before OneKey’s post. The bulletin states plainly that Ledger has no evidence the bug was exploited against any user. The bug was not something a remote attacker could pull off on its own. TestMachine’s own writeup described the precondition as a malicious dApp with WebHID access racing a command into the device during the review screen, meaning the wallet had to already be connected to a compromised or malicious site or application for the swap to happen.
Ledger has faced this kind of dispute before without it holding up. In June, a user reported losing 2.3 million ADA from a Ledger wallet without signing anything, a claim that was never backed by public on-chain evidence.

Ledger Ethereum Ap
OneKey’s demonstration was not the first time this fixed bug resurfaced publicly. Security firm TestMachine described a matching issue around August 21 to 23, days after Ledger’s SDK patch and before OneKey’s post. We covered that earlier round of the dispute when Ledger had not yet published a public bulletin for it, and when affected models spanned the Nano X, Nano S Plus, Stax, Apex and Flex lines. Both disclosures landed on a version of the software Ledger had already retired.
Ledger’s CTO, Charles Guillemet, has pushed back directly on both outside disclosures, saying the flaw was actually found first by Ledger’s own Donjon team through AI-assisted vulnerability research, and criticizing TestMachine for going public without properly coordinating with Ledger once a fix already existed.
Ledger used the same day as OneKey’s post to publish two further bulletins covering unrelated signing flows: a clear-signing bypass affecting Ethereum app versions 1.19.0 through 1.22.2, and a swap-flow issue affecting versions 1.20.0 through 1.22.2 that could accept a token approval in place of a payment. Both were fixed in version 1.22.3, and neither bulletin lists any confirmed loss.
Ledger is advising users to update to 1.22.3 or later on both firmware and the Ethereum app through Ledger Live, and to check the app version on the device screen itself, since the two update separately. We have reached out to OneKey for comment and haven’t received any reply.