Security Researchers Replicate Ledger Hardware Wallet Vulnerability
OneKey founder Yishi Wang has confirmed that the company's Anzen security team successfully reproduced a transaction replacement attack against Ledger's Ethereum app, version 1.22.1, in a controlled lab environment. This type of attack could potentially allow malicious actors to alter transaction details after a user believes they have approved a legitimate transfer, putting cryptocurrency funds at risk.
Hardware wallets like Ledger are widely trusted for securely storing digital assets, precisely because they are designed to isolate private keys from internet-connected devices. However, this finding underscores that even hardware-based security solutions can contain exploitable flaws in their software layers, particularly in how transaction data is displayed and confirmed to users.
For Australian small businesses that hold or transact in cryptocurrency, this development is a reminder that no security device is infallible. Businesses relying on hardware wallets should stay alert for firmware updates from Ledger addressing this issue and exercise caution when confirming transaction details on-device.