OneKey Security Team Successfully Recreates Exploit on Legacy Ledger Ethereum Application

OneKey Security Team Successfully Recreates Exploit on Legacy Ledger Ethereum Application

In a controlled laboratory setting, OneKey successfully replicated a security exploit targeting an earlier iteration of Ledger's app, a vulnerability that was subsequently patched in Ledger's Ethereum app version 1.22.2 without any loss of customer assets.

Security researchers working within OneKey, a provider of open-source cryptocurrency wallets, announced they successfully replicated a security exploit that targeted a previous version of Ledger's device-based Ethereum application within a controlled testing environment.

According to Yishi Wang, who serves as both founder and chief executive officer of OneKey, their team conducted a "transaction replacement attack" on version 1.22.1 of Ledger's Ethereum app by taking advantage of a security flaw that has since been patched, which allowed malicious actors to replace the transaction awaiting signature while users were still examining the original legitimate transaction on their screens.

According to Ledger's assessment, successfully exploiting this security flaw required attackers to gain control over the communication channel between the hardware device and the connected host system, which could occur through various means including malicious software, compromised wallet applications, or malicious web pages. Ledger implemented additional security measures at the application level with the release of Ethereum app version 1.22.2 on Aug. 13, then addressed the fundamental issue at a deeper level in Secure SDK version 26.6.1, which was released on Aug. 21.

No Ledger user was hacked. What's described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app.

Ledger in a Thursday X post

This security testing initiative comes in the wake of the Coldcard security incident that occurred in July, during which threat actors leveraged a firmware defect that was first introduced in March 2021, which compromised the seed randomness generation on certain Coldcard wallet units, making the generated private keys susceptible to brute-force attack methodologies.

In earlier statements, Ledger had clarified that its hardware devices remained unaffected by the security vulnerability discovered in Coldcard products, explaining that their recovery phrases are created using a certified randomness source that is integrated directly into the security chip of the device.

The security vulnerability that OneKey replicated in their laboratory environment bears no connection to the seed generation process and instead impacts the manner in which transactions are processed and managed throughout the signing procedure.