The dispute centers on a time-of-check to time-of-use race condition that allowed for transaction substitution. By exploiting a weakness in how the device handled Application Protocol Data Unit (APDU) commands, an attacker could theoretically overwrite signing parameters while a user reviewed a transaction on the device screen. This flaw bypassed the hardware wallet's trusted-display guarantee, potentially causing a user to approve a different transaction than the one shown.
Ledger Chief Technology Officer Charles Guillemet characterized the OneKey demonstration as a laboratory exercise against legacy software rather than a breach of the company’s security infrastructure. Records indicate that Ledger released Ethereum app version 1.22.2 on August 13, which introduced state checks to block the substitution path, followed by a Secure SDK update on August 21 that prevented interleaved commands entirely. Ledger confirmed no evidence exists that this vulnerability was ever leveraged to cause user losses or unauthorized asset transfers.
Comments (0)
No comments yet. Be the first!