Ledger Denies Hack Claims as Patched Ethereum App Vulnerability Comes to Light

Ledger denies hacking allegations
Table of Contents

TL;DR:

  • The vulnerability affected version 1.22.1 of the Ethereum app for Ledger and allowed a race condition that replaced transactions before signing.
  • The manufacturer patched the initial flaw on August 13, 2026, in version 1.22.2 and strengthened the system with Secure SDK 26.6.1 on August 21, 2026.
  • The company published its official security bulletin on August 27, 2026, confirming the absence of active exploits in real-world environments.

Ledger denies hacking allegations after demonstrations of a technical flaw in outdated versions of its Ethereum application were published, clarifying—on Thursday, August 27—that the security patch was deployed prior to its public disclosure.

The controversy began when security researchers from rival firm OneKey posted on social media that they had managed to recreate an attack in a lab setting. Regarding this, OneKey CEO Yishi Wang stated that the weakness stemmed from a race condition between the data buffer and the physical device’s visual interface.

This flaw allowed an attacker with control over the intermediary software to overwrite a transaction while the user was reviewing the legitimate operation on screen. Technical data shared by the researchers indicates that this vector could redirect funds to external wallets without reflecting the modification on the physical device.

Ledger’s Chief Technology Officer, Charles Guillemet, immediately rejected the narrative of a security breach in the manufacturer’s infrastructure. The company’s official documentation notes that reproducing a bug on an obsolete version within a lab does not constitute an active vulnerability or a compromise of user funds.

Patch Timeline and Technical Details of the Vulnerability

Ledger denies hacking allegations

The issue originated in the internal application designed to manage transactions on the Ethereum network and compatible tokens. In version 1.22.1, a malicious web application with permissions to connect to the device could send a secondary signing instruction while the user was examining the first.

The manufacturer identified the issue internally and rolled out update 1.22.2 on August 13, 2026. The firm’s report details that the changes introduced two key safeguards: rejecting new signing sessions while a review is underway and voiding confirmations if the memory state differs from what is displayed on the screen.

To secure the application ecosystem, the development team updated its software development kit (Secure SDK) to version 26.6.1 on August 21, 2026. Through this procedure, the company rebuilt the entire application catalog to prevent similar vectors across other digital assets.

The bulletin issued on August 27, 2026, specifies that an attack of this nature required the host computer to be previously compromised by malware or connected to a malicious web platform. Additionally, the technical report confirms that the private keys stored in the hardware’s secure element were never exposed.

The Ledger Donjon security research team noted that this incident highlights the need for regular update practices on cold wallets. The modular hardware architecture allows patches to be applied to peripheral software without compromising the original recovery seed.

To verify device protection, users should check in Ledger Live that the Ethereum app is updated to version 1.22.3 or higher. The manufacturer will continue monitoring its software repositories and will publish new update logs in its application manager during upcoming scheduled reviews.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews