
Ledger Disputes OneKey's Vulnerability Claim, Says Flaw Was Already Patched
Security researchers at OneKey demonstrated a flaw in Ledger's Ethereum app that could display one transaction on screen while signing a different one, but Ledger says the vulnerability was already fixed before the public disclosure. The dispute centers on whether the exploit represents a current security risk.
Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work
The Vulnerability Demonstration
OneKey researchers reproduced a flaw in Ledger's Ethereum app that allowed a malicious smart contract to sign a transaction different from the one displayed on the device's screen. The exploit leveraged an outdated version of the app to execute this transaction-signing mismatch, creating a scenario where a user could approve one action while unknowingly authorizing another.
Ledger's Response
Ledger rejected characterizations of the demonstration as a current hack or active vulnerability, stating the flaw had already been patched before OneKey's public disclosure. The company did not dispute that the vulnerability existed in earlier versions of the Ethereum app, only that it remained a live risk to users running up-to-date software. Ledger did not provide a specific date for when the patch was deployed or technical details of the fix.
Implications for Hardware Wallet Users
The disagreement highlights the gap between proof-of-concept demonstrations on legacy software and actual user exposure. Users running the latest version of Ledger's Ethereum app are not affected if Ledger's patching timeline is accurate. However, the incident underscores the importance of keeping hardware wallet firmware and apps current, as delayed updates could leave users exposed to known vulnerabilities.
Why It Matters
For Traders
If you use a Ledger device for Ethereum transactions, updating to the latest app version protects against this signing mismatch; delayed updates could expose you to the vulnerability.
For Investors
Ledger's rapid response and pre-existing patch suggest mature security practices, though the public disclosure gap raises questions about vulnerability disclosure timelines.
For Builders
Hardware wallet integrations should enforce minimum app version requirements in dApps to prevent users from interacting with contracts on outdated, vulnerable firmware.
This article is for information only and is not financial advice. Read the full disclaimer.






