No, Ledger Wasn’t Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says
Covered by 2 sources · 2 articles
Security researcher OneKey claimed to have identified a vulnerability in Ledger's Ethereum app where the device could sign a transaction different from what appeared on its screen - a serious concern for hardware wallet users who rely on display verification. Ledger acknowledged the flaw existed but stated it had already patched the issue before OneKey publicized the discovery. The company disputed OneKey's characterization, saying the team merely replicated already-known findings rather than conducting an independent exploit.
The dispute centers on timing and attribution. OneKey's Anzen security team framed its work as a successful hack, while Ledger positioned the disclosure as after-the-fact validation of a problem it had resolved. Neither party disputes the vulnerability itself existed; the disagreement is whether OneKey discovered it or demonstrated a pre-existing weakness.
- Ledger's Ethereum app contained a flaw allowing mismatched transaction signing, but the company claims it was patched before public disclosure.
- OneKey and Ledger contest whether the security team uncovered a new vulnerability or simply reproduced a known issue Ledger had already fixed.
- The incident highlights the importance of coordinated disclosure timelines in hardware wallet security.
All coverage
No, Ledger Wasn’t Hacked: Vulnerable Ethereum App Was Patched Before Exploit, Company Says
OneKey demonstrated how an outdated Ethereum app could sign a transaction different from the one shown on a Ledger device, but the wallet maker says the vulnerability had already been fixed.
OneKey ‘hacked’ already-patched Ledger app
OneKey's Anzen security team claims it hacked Ledger's Ethereum app, while Ledger says it just copied its findings.