
OneKey Replicates Transaction Replacement Exploit on Older Ledger Ethereum App
Vexoda Newsroom
Security firm OneKey successfully reproduced a transaction replacement attack on an outdated Ledger Ethereum app in a lab setting. Ledger confirmed the vulnerability was patched and no user funds were
Open-source wallet provider OneKey's in-house security team has successfully demonstrated a transaction replacement attack in a controlled laboratory environment. The exploit specifically targeted an older, now-patched version of Ledger's on-device Ethereum application. This type of attack involves manipulating a transaction while it is awaiting user confirmation, potentially tricking the user into signing a different, malicious transaction than they intended. OneKey's findings highlight the ongoing importance of diligent security audits in the cryptocurrency hardware wallet space.
The key players in this incident are OneKey, the security researcher that identified and reproduced the exploit, and Ledger, the manufacturer of the affected hardware wallet. Specifically, the vulnerability was found in Ledger Ethereum app version 1.22.1. OneKey's CEO, Yishi Wang, confirmed that the attack was executed by exploiting a previously identified flaw that allows for the overwriting of legitimate transactions with fraudulent ones during the signing process.
Understanding this exploit requires context about hardware wallet security. Hardware wallets like Ledger's are designed to keep private keys offline, offering a robust defense against online threats. However, vulnerabilities can arise in the software that interfaces with the hardware. This specific "transaction replacement attack" exploits a flaw in how the Ethereum app on the device handles transaction data presented to the user for approval, making it crucial that users always use the latest software versions.
Ledger has addressed the situation by stating that no user funds were compromised and that the vulnerability was purely a lab reproduction. The company confirmed that Ledger Ethereum app version 1.22.2, released on August 13th, includes app-level safeguards against this issue. Furthermore, the underlying vulnerability was fixed in Secure SDK version 26.6.1 on August 21st, well before OneKey's public disclosure. This demonstrates Ledger's prompt response to patching security concerns.
This incident, while contained and resolved, underscores the critical need for continuous security vigilance for all hardware wallet users. It is unrelated to seed generation or recovery phrases, unlike a recent Coldcard firmware issue, and focuses solely on the transaction signing process. The ability for a security firm to reproduce such an attack, even in a lab, emphasizes the dynamic nature of cybersecurity and the importance of staying updated with the latest software and firmware patches provided by hardware wallet manufacturers.
For traders and cryptocurrency holders, the primary takeaway is the imperative to keep all wallet software and firmware updated to the most recent versions. Ledger has confirmed that their app version 1.22.2 and subsequent SDK updates have mitigated this specific threat. Users should also be aware of the conditions under which such an attack could theoretically be executed, such as malware or compromised host software, and practice safe computing habits when interacting with their hardware wallets.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.