OneKey founder and CEO Yishi Wang announced that the OneKey Anzen team successfully reproduced a transaction swap attack targeting the Ethereum app for Ledger hardware wallets. The affected version is ledger ethereum app 1.22.1, according to the official statement.
What OneKey Said
According to Yishi Wang, researchers managed to replicate the attack against the Ethereum app on Ledger devices. He emphasized that their testing took place in a controlled lab environment and specifically impacts version 1.22.1.
The Vulnerability Explained
This issue lets an attacker swap out a transaction in the Ethereum app for Ledger hardware wallets. The statement doesn't go into technical details or share exactly how the exploit works.
What We Know So Far
News of the vulnerability and its reproduction comes from Yishi Wang's public post. No other specifics—like how the bug actually works or what other setups might be at risk—were shared in the announcement.
