OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app
Source Entity
Cointelegraph by Zoltan Vardai

OneKey security researchers have reproduced a transaction replacement exploit targeting outdated Ledger Ethereum app versions. Ledger had previously patched this vulnerability in version 1.22.2, and no user funds were reported lost during the reproduction process.
Security Vulnerability in Legacy Ledger Firmware
The recent disclosure by the security team at OneKey regarding a successful reproduction of a transaction replacement attack on older Ledger Ethereum applications highlights the critical nature of hardware wallet maintenance. By targeting version 1.22.1, the researchers were able to demonstrate how a vulnerability, which has since been addressed in version 1.22.2, could theoretically allow an attacker to overwrite a transaction while it is awaiting user approval on the hardware device.
Understanding the Transaction Replacement Attack
According to OneKey founder and CEO Yishi Wang, the attack vector involves manipulating the communication flow between the hardware wallet and the host device. By exploiting the specific logic within the outdated Ethereum app, an attacker could potentially swap the intended transaction details for malicious ones while the user is still in the process of reviewing the original, legitimate request. This type of 'man-in-the-middle' scenario underscores the importance of strict communication protocols between hardware signing devices and the software interfaces that facilitate them.
The Importance of Patching and Firmware Integrity
It is vital to emphasize that Ledger had already identified and mitigated this specific vulnerability in the 1.22.2 release. The fact that OneKey was able to reproduce the exploit only in a controlled lab environment—and specifically on outdated software—reinforces the necessity for users to maintain the latest firmware and application versions on their hardware devices. In the ecosystem of self-custody, failing to update firmware is akin to leaving a digital door unlocked, even if the manufacturer has already provided the necessary security updates.
Security Context and Risk Mitigation
Ledger has clarified that executing such an attack would require the perpetrator to maintain control over the communications between the hardware wallet and the host computer. This prerequisite significantly raises the barrier for entry for any potential attacker, requiring a compromised host environment. Despite the complexity, the demonstration serves as a stark reminder of the evolving threat landscape facing cold-storage solutions.
Broader Implications for Cryptocurrency Custody
This incident serves as a case study in the collaborative nature of security research within the open-source and hardware wallet sectors. While competition exists between companies like OneKey and Ledger, the shared goal of hardening infrastructure against potential exploits benefits the entire crypto-asset community. Moving forward, the industry must continue to prioritize transparent patching processes and user education regarding the necessity of regular updates to ensure that the promise of self-custody remains robust against sophisticated digital threats.