Ledger rejects hack claim after OneKey recreates bug

1 hour ago 1



Ledger rejected claims that it had been hacked after OneKey’s Anzen security team reproduced a transaction replacement flaw against an outdated version of Ledger’s Ethereum application. Summary OneKey reproduced a transaction substitution attack against Ledger Ethereum app version 1.22.1 in laboratory testing. Ledger says Ethereum app 1.22.2 added safeguards before OneKey publicly described its reproduction attempt online. An attacker needed control over device-host communications through malware, hostile webpages or compromised wallet software. Secure SDK version 26.6.1 blocked interleaved commands before they reached individual Ledger device applications directly. Ledger found no evidence the vulnerability was exploited against users or caused cryptocurrency losses anywhere. OneKey founder Yishi Wang said on Aug. 27 that researchers completed the attack against Ethereum app 1.22.1 in a laboratory. Ledger confirmed the underlying vulnerability but said it had already patched the affected application before OneKey published its demonstration. Ledger Ethereum flaw broke the trusted display guarantee The vulnerability involved communication between a Ledger device and its connected h...

Read Entire Article