we hacked ledger.
the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab.
the bug is a race condition between the transaction display logic and the underlying transaction buffer.
an attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one.
in simple terms:
- you see transaction a on your ledger.
- you approve transaction a.
- your ledger can end up signing transaction b.
- and you never see transaction b.
to reproduce this, we built the 1.22.1 ELF ourselves, fixed the speculos reset 502 issue, and got the full attack flow working end to end.
ledger fixed this in ethereum app 1.22.3.
if you’re still on an older version, update it.
OneKey Reddit Party claim update:
Reddit limits replies, so we’ll contact winners from the official OneKey X account.
Add X to the Reddit profile used for your entry and open your X DMs. We’ll send your claim code there.
Deadline: Aug 31, 11:59 PM (UTC+8).
Post and chat with us on Reddit for a chance to win!
Aug 17–24: Share a crypto security tip or a OneKey story in r/onekeyhq with a photo of your OneKey.
20 winners:
🎁 5 × OneKey Classic 1S Pure BTC-Only
🎁 15 × OneKey merch bundles
🔗 https://t.co/XG590uOejE
eight months ago, i handed my boss @cz_binance the prototype. he said, “keep going, make it great.”
today, in bhutan, i finally handed him the new one.
pretty proud to say i think we’ve built the best hardware wallet experience in the world. hope he likes it hehe.
the team won’t let me leak a single detail yet, so that’s all i can say for now. but give us a little more time. i think you’ll be meeting it very soon :)