DropsTab logo - blue line depicting the shape of a water drop with Christmas decoration
M. Cap: $2.68 T −1.13%24h Vol: $155.79 B 7.17%BTC: $79,398.70 −1.09%ETH: $2,506.82 −0.48%S&P 500: $7,761.53 0.43%Gold: $4,560.29 −0.77%BTC Dominance: 59.35%

The founder of OneKey stated that his team “hacked” Ledger.

28 Aug, 2026byDropsTab
Join Our Socials

OneKey founder Yishi reported that his team reproduced in the lab a transaction-spoofing attack on the Ledger Ethereum App. The essence: due to a race condition in the code, an attacker can substitute a transaction while the user is still looking at the screen. The user sees and approves transaction A, but the device signs transaction B, which the user never saw.

The described bug matches a vulnerability that was already publicly disclosed on August 22 by independent researcher TestMachine, and Ledger fixed it in version 1.22.2, not 1.22.3 as Yishi claimed.

Ledger itself confirmed the issue in LSB 023: some applications on the Ledger Secure SDK could accept new commands during confirmation on the screen, causing the displayed parameters to differ from those actually signed. The problem lies in the input/output handling within the SDK, not in the device firmware. SDK version 26.6.1 was released on August 21; users need to update their applications specifically through Ledger Live.

Ledger has not yet recorded any real-world cases of exploitation of this vulnerability.

Continue reading this article on source: x.com