A public disagreement between hardware wallet makers Ledger and OneKey over a reproduced vulnerability in an outdated version of Ledger's Ethereum application highlights how much disclosure language matters in security reporting — and how quickly "we hacked Ledger" travels before context catches up.
What Happened
On August 27, OneKey founder Yishi Wang wrote on X that the company's Anzen security team had "hacked Ledger," having successfully reproduced a transaction replacement attack against Ledger Ethereum app version 1.22.1 in laboratory testing.
The claim was technically grounded. According to OneKey's description and Ledger's own security bulletin, the flaw is a race condition between the transaction display logic and the underlying transaction buffer. A second command delivered to the device while the user is reviewing one transaction can overwrite the signing parameters without updating the screen. The user reviews and approves transaction A; the device signs transaction B. Ledger classified the issue as a time-of-check to time-of-use race condition that defeats the trusted-display guarantee hardware wallets depend on.
The flaw does not expose seed phrases or extract private keys from the secure element. Exploitation requires an attacker to already control the communication channel between the device and its host — through malware, a compromised wallet application, or a hostile webpage with WebHID or WebUSB access — and the user must still approve a transaction while the manipulation is underway.
Ledger's Response: Patched Before the Demonstration
Ledger confirmed the underlying vulnerability but rejected the framing. Chief Technology Officer Charles Guillemet said that "reproducing an already-patched bug is not 'hacking Ledger,'" and the company says it has found no evidence the flaw was ever exploited against users or caused any losses.
The version history supports a more precise timeline than either side's headline:
- Ethereum app 1.22.2, released August 13, added application-level state checks designed to stop the transaction substitution path — before OneKey's public demonstration.
- Secure SDK 26.6.1, released August 21, blocks interleaved commands before they reach application code at all.
- Ethereum app 1.22.3 carries the broader SDK protection and addresses an additional transaction-display flaw. Ledger recommends all users update to this version or later.
OneKey's statement that 1.22.3 is protected was accurate, but the first application-level fix shipped in 1.22.2, two weeks before the public reproduction.
What Users Should Take From It
Both companies agree on the substance: the flaw existed, it was real, and it is fixed in current releases. The dispute is about framing and credit, not about whether current Ledger firmware is vulnerable. For users, the practical guidance is simple — keep device firmware and individual currency applications updated, since exposure was application-specific and the protections arrived through app updates rather than a single firmware patch.
The episode also illustrates a disclosure etiquette point that this publication holds to: a laboratory reproduction of a patched flaw is valuable research, but it is not an incident. Incidents require evidence of exploitation. As of August 30, none has been presented by either side.