cleartext

Independent, sourced crypto news. No paid placements.

ledger

Ledger and OneKey trade claims over an Ethereum app bug that was already patched

Rival hardware wallet maker OneKey says it reproduced a transaction-replacement exploit against Ledger's Ethereum app version 1.22.1; Ledger says the flaw was patched weeks earlier and no user was affected.

A competing hardware wallet vendor said on Thursday that it had "hacked Ledger." Ledger's response, several hours later, was that reproducing a bug someone else already fixed is a lab exercise, not a break-in. Both statements can be true at once, which is roughly what happened.

According to Protos, OneKey founder Yishi Wang published a walkthrough on 27 August describing how his security team, working with cybersecurity firm Anzen, reproduced a transaction replacement attack against version 1.22.1 of Ledger's Ethereum app. Protos reported that the attack takes place while a user is reviewing a legitimate transaction — the moment at which a hardware wallet's on-device screen is supposed to be the final, tamper-proof check on what is actually being signed. Wang's post, per Protos, carried both the claim "We hacked ledger" and a warning that users still on the older Ethereum app should update.

That warning is the part that complicates the framing. By OneKey's own account, as relayed by Protos, Ledger had already fixed the issue — Wang pointed users to version 1.22.3.

Ledger disputes the characterisation, not the existence of the bug. Chief Technology Officer Charles Guillemet responded that "reproducing an already-patched bug is not 'hacking Ledger,'" adding: "No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding." A Ledger spokesperson told Protos that OneKey "took the already disclosed findings and tried to replicate them in a lab environment." Decrypt covered the dispute the same evening under the headline "No, Ledger Wasn't Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says" — corroborating the shape of the story and, in its framing, Ledger's account of it.

Where the two sides don't line up

The most concrete discrepancy is the patch itself. Wang said the fix landed in 1.22.3. Ledger's in-house security team, Donjon, said the fix shipped on 13 August in version 1.22.2 — a claim Protos characterised as further contradicting OneKey. Nobody has reconciled those two version numbers publicly. The plausible readings are that Donjon's 1.22.2 carried the fix and OneKey pointed at the newest available build, or that 1.22.2 was incomplete and 1.22.3 finished the job. Neither company has said which, and Protos reported that it had asked OneKey for comment without a response at the time of publication.

The second gap is the origin of the finding. Ledger's spokesperson called these "already disclosed findings," which implies a prior public advisory — but neither report identifies who originally found the flaw, when it was disclosed, through what channel, or whether OneKey and Anzen reported anything to Ledger before publishing. If Donjon shipped the patch on 13 August, that leaves a two-week window between the fix and OneKey's demonstration, during which any user who had not updated their Ethereum app was, by both parties' logic, running vulnerable firmware.

Neither company has published a CVE identifier, a severity rating, or the technical preconditions the attack requires — whether the victim's host machine must already be compromised, for instance, which for this class of attack is usually the decisive question. Ledger has not said how many users remain on affected versions.

Key facts

  • OneKey and Anzen say they reproduced a transaction replacement attack against Ledger's Ethereum app version 1.22.1 (Protos, 27 August).
  • OneKey founder Yishi Wang said Ledger had already fixed the issue in version 1.22.3 and urged users to update (Protos).
  • Ledger's Donjon team said the fix shipped on 13 August in version 1.22.2 (Protos).
  • Ledger CTO Charles Guillemet: "No user was hacked. No exploitation in the wild" (Protos).
  • A Ledger spokesperson said OneKey replicated "already disclosed findings" in a lab environment (Protos).
  • Decrypt reported the same dispute, framing it as a patched vulnerability rather than a breach (Decrypt, 27 August).
  • OneKey had not responded to Protos's request for comment as of publication.

The real-world read

OneKey is not a neutral researcher. It sells hardware wallets in direct competition with Ledger. "We hacked ledger" from a rival vendor's founder is a marketing statement wearing a security-research jacket, and it should be discounted accordingly — particularly given that the same post told users the bug was already fixed. A finding that comes with its own remediation notice is, definitionally, not a live break.

Ledger's rebuttal is also doing work. "No user was hacked" and "no exploitation in the wild" are narrower claims than they sound. They do not dispute that the vulnerability was real, that it affected a shipping version of Ledger's Ethereum app, or that it required a patch. Absence of observed exploitation is not the same as absence of exploitation, and Ledger is the interested party attesting to it. What Ledger has not offered is any evidence for the negative — no telemetry, no scope.

The version numbers are a small mess with a real implication. Ledger's own team says 1.22.2, on 13 August; OneKey says 1.22.3. Ledger cannot simultaneously present a tidy "already patched, nothing to see" narrative and leave unresolved which build actually contains the fix — users deciding whether they are safe need that answer, and it isn't public.

Left conspicuously unsaid on both sides: the original disclosure trail, the attack's preconditions, any severity assessment, and whether OneKey coordinated with Ledger at all. Protos also notes prior coverage of Ledger customer data exposed in a third-party Global-e breach and of a fake Ledger app used to move $9.5 million — separate incidents, unrelated to this bug, but context for why "Ledger" and "hack" in the same sentence travels fast regardless of the technical merits.

Opinion, and whose

  • Yishi Wang (OneKey founder): frames the reproduction as "We hacked ledger" — an interested party's characterisation, published alongside advice to update.
  • Charles Guillemet (Ledger CTO): argues that running an exploit against an old version after a fix ships is "a lab exercise, not a finding." Also an interested party, and a defensible position on disclosure norms rather than a verifiable fact.
  • Decrypt: its headline treatment sides with the patched-before-exploit reading.
  • Protos: presents the two accounts against each other and flags the Donjon patch-version contradiction without resolving it.

No independent third party has published a technical verification of either the exploit or the patch timeline.

Sources

  • Protos (27 August 2026, 18:12 UTC) — the substantive account: Wang's claim and warning, Guillemet's quoted rebuttal, the Ledger spokesperson's statement, and Donjon's 13 August / 1.22.2 patch claim. Also noted OneKey had not responded to its comment request.
  • Decrypt (27 August 2026, 18:16 UTC) — corroborates that the dispute occurred and that Ledger's position is that the app was patched before the exploit; its published page carried a live price ticker rather than additional reported detail on the incident.
  • Neither company's own advisory, changelog, or release notes for versions 1.22.1 through 1.22.3 has been cited by either outlet.
  • No sponsored or commissioned material was used. OneKey's claim is treated here as a competitor's promotional statement, and Ledger's response as a vendor defending its product.

Nothing here is financial advice. If you use a Ledger device with the Ethereum app, updating to the current version is a security decision, not an investment one.