BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

OneKey Reproduces Transaction Replacement Attack on Outdated Ledger Ethereum App

Hardware wallet maker OneKey says it reproduced a transaction replacement attack against an outdated version of Ledger's Ethereum app, a claim that spotlights the risks of running legacy firm

AnonymousCryptoCompass newsroom
August 28, 2026
4 min read
NEWS
OneKey Reproduces Transaction Replacement Attack on Outdated Ledger Ethereum App
CryptoCompass editorial visual for altcoins coverage.

Hardware wallet maker OneKey says it reproduced a transaction replacement attack against an outdated version of Ledger's Ethereum app, a claim that spotlights the risks of running legacy firmware even as it stops short of implicating current, updated software.

The report circulated through security researcher posts on X, where the reproduction of the issue was demonstrated against an older build of the Ledger Ethereum application. The claim remains narrowly scoped: it targets an outdated app version rather than the entire product line. For related coverage, see UK Government Reports 240 Crypto Millionaires in 2025.

What OneKey says it reproduced

A transaction replacement attack, in plain terms, refers to a scenario where the data a user believes they are signing is swapped for different transaction details before the signature is finalized. The danger is that a wallet screen could display one action while the device actually authorizes another. For related coverage, see Visa Works With Upbit Parent on Stablecoin Payments, AI Commerce.

OneKey is credited as the party that reproduced the behavior, according to a researcher post on X describing the test. Because the reproduction was tied to an outdated Ledger Ethereum app, the finding is a demonstration of legacy-version risk rather than a confirmed flaw in the latest release. For related coverage, see Abu Dhabi Royal Backs 49% Stake in Trump-Linked Crypto Bank.

The underlying software is Ledger's open-source Ethereum application, whose code and revision history are public on the LedgerHQ app-ethereum repository. That transparency lets outside developers, including competitors like OneKey, inspect and test behavior across versions.

Why the "outdated" qualifier is the whole story

The specific detail that matters here is the app's software state. The reproduction is described against an outdated build, which means the vulnerability framing depends on the version being run, not simply on the Ledger brand.

That distinction cuts against any conclusion that every Ledger Ethereum app is affected. Ongoing changes to the application are tracked in the project's public changelog, where fixes and feature updates are logged over time. Whether the reproduced behavior persists in current builds is the open question the report itself does not resolve.

For readers, the practical takeaway is version awareness. A reproduced attack on legacy software says more about update hygiene than about the security of a fully patched device.

What it means for wallet users

A reproduced attack naturally raises questions about exposure, and the most direct user response is to verify which app version is installed and whether updates are pending. Hardware wallet security frequently turns on this kind of maintenance discipline rather than on any single headline flaw.

The cross-brand framing, a OneKey test against a Ledger app for Ethereum, gives the story industry-wide relevance around trust in transaction verification. OneKey has been active on the feature side as well, recently rolling out a tool to borrow gas fees for TRON transactions, underscoring the competitive backdrop against which these security disclosures land.

Security incidents across the sector keep the spotlight on how projects respond, from patch cadence to user compensation, as seen when The Sandbox pledged 1:1 repayment after a bridge exploit. In each case, the response to a disclosed issue often shapes user trust as much as the underlying technical detail.

Given the weak, single-source nature of the current reporting, the responsible reading is cautious: the demonstration is tied to an outdated app, and confirmation of scope, affected versions, and any vendor response remains outstanding.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Read original article on coinwy.comRead also :