OneKey Founder Says Team “Hacked” the Largest Hardware Wallet, Ledger OneKey founder Yishi said the OneKey Anzen team reproduced a transaction-replacement attack on Ledger Ethereum App 1.22.1 in the lab.
He said a race condition between display logic and the transaction buffer could let an attacker overwrite a pending transaction while the user reviews a legitimate one, so the user may approve transaction A while the device signs transaction B without showing it
Yishi said Ledger fixed it in Ethereum App 1.22.3. X community notes said the bug matches a vulnerability disclosed by TestMachine on August 22 and fixed by Ledger in Ethereum App 1.22.2, not 1.22.3. Ledger disclosed LSB 023, saying some apps built with Ledger Secure SDK could still receive new APDU commands during on-screen confirmation, causing displayed parameters to differ from those signed.
Ledger said the issue is in the SDK’s I/O handling, not the device OS or firmware, and was fixed through app-level checks and SDK changes. SDK v26.6.1 was released on August 21; users must update apps via Ledger Live, as firmware updates alone are not enough. Ledger said there is no evidence of exploitation. — link