Ledger Disputes OneKey's Vulnerability Claim, Says Flaw Was Already Patched
SecurityExchanges
Neutral

Ledger Disputes OneKey's Vulnerability Claim, Says Flaw Was Already Patched

Security researchers at OneKey demonstrated a flaw in Ledger's Ethereum app that could display one transaction on screen while signing a different one, but Ledger says the vulnerability was already fixed before the public disclosure. The dispute centers on whether the exploit represents a current security risk.

Aug 28, 2026, 05:02 AM1 min read

Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work

The Vulnerability Demonstration

OneKey researchers reproduced a flaw in Ledger's Ethereum app that allowed a malicious smart contract to sign a transaction different from the one displayed on the device's screen. The exploit leveraged an outdated version of the app to execute this transaction-signing mismatch, creating a scenario where a user could approve one action while unknowingly authorizing another.

Ledger's Response

Ledger rejected characterizations of the demonstration as a current hack or active vulnerability, stating the flaw had already been patched before OneKey's public disclosure. The company did not dispute that the vulnerability existed in earlier versions of the Ethereum app, only that it remained a live risk to users running up-to-date software. Ledger did not provide a specific date for when the patch was deployed or technical details of the fix.

Implications for Hardware Wallet Users

The disagreement highlights the gap between proof-of-concept demonstrations on legacy software and actual user exposure. Users running the latest version of Ledger's Ethereum app are not affected if Ledger's patching timeline is accurate. However, the incident underscores the importance of keeping hardware wallet firmware and apps current, as delayed updates could leave users exposed to known vulnerabilities.

Why It Matters

For Traders

If you use a Ledger device for Ethereum transactions, updating to the latest app version protects against this signing mismatch; delayed updates could expose you to the vulnerability.

For Investors

Ledger's rapid response and pre-existing patch suggest mature security practices, though the public disclosure gap raises questions about vulnerability disclosure timelines.

For Builders

Hardware wallet integrations should enforce minimum app version requirements in dApps to prevent users from interacting with contracts on outdated, vulnerable firmware.

This article is for information only and is not financial advice. Read the full disclaimer.

Live prices:Ethereum

Related Articles

Latest News