Yishi|Aug 27, 2026 12:34
we hacked ledger.
the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab.
the bug is a race condition between the transaction display logic and the underlying transaction buffer.
an attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.
in simple terms:
- you see transaction a on your ledger.
- you approve transaction a.
- your ledger can end up signing transaction b.
- and you never see transaction b.
to reproduce this, we built the 1.22.1 ELF ourselves, fixed the speculos reset 502 issue, and got the full attack flow working end to end.
ledger fixed this in ethereum app 1.22.3.
if you’re still on an older version, update it.(Yishi)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink