Ledger Denies Hack Claims as Patched Ethereum App Vulnerability Emerges

DN19 Newsroom
28 Aug 2026 00:40
Coins 0 6
3 minutes reading

Ledger has denied hacking allegations following the publication of a laboratory demonstration showing a technical flaw in an outdated version of its Ethereum application. The hardware wallet manufacturer clarified on Thursday, August 27, 2026, that the security patch had been deployed prior to the public disclosure of the vulnerability.

No Ledger user was hacked.
What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app.
The issue was already identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post. The…
— Ledger (@Ledger) August 27, 2026

Origin of the Controversy

The controversy began when security researchers from rival firm OneKey posted on social media that they had successfully recreated an attack in a controlled lab setting. OneKey CEO Yishi Wang stated that the weakness stemmed from a race condition between the data buffer and the physical device’s visual interface. This flaw allowed an attacker with control over the intermediary software to overwrite a transaction while the user was reviewing the legitimate operation on screen. Technical data shared by the researchers indicates that this vector could redirect funds to external wallets without reflecting the modification on the physical device.

Ledger’s Response and Technical Rebuttal

Ledger’s Chief Technology Officer, Charles Guillemet, immediately rejected the narrative of a security breach in the manufacturer’s infrastructure. The company’s official documentation notes that reproducing a bug on an obsolete version within a lab does not constitute an active vulnerability or a compromise of user funds. The bulletin issued on August 27, 2026, specifies that an attack of this nature required the host computer to be previously compromised by malware or connected to a malicious web platform. Additionally, the technical report confirms that the private keys stored in the hardware’s secure element were never exposed.

Patch Timeline and Technical Details of the Vulnerability

The issue originated in the internal application designed to manage transactions on the Ethereum network and compatible tokens. In version 1.22.1, a malicious web application with permissions to connect to the device could send a secondary signing instruction while the user was examining the first.

The manufacturer identified the issue internally and rolled out update 1.22.2 on August 13, 2026. The firm’s report details that the changes introduced two key safeguards: rejecting new signing sessions while a review is underway and voiding confirmations if the memory state differs from what is displayed on the screen.

To secure the application ecosystem, the development team updated its software development kit (Secure SDK) to version 26.6.1 on August 21, 2026. Through this procedure, the company rebuilt the entire application catalog to prevent similar vectors across other digital assets.

User Guidance and Ongoing Monitoring

The Ledger Donjon security research team noted that this incident highlights the need for regular update practices on cold wallets. The modular hardware architecture allows patches to be applied to peripheral software without compromising the original recovery seed.

To verify device protection, users should check in Ledger Live that the Ethereum app is updated to version 1.22.3 or higher. The manufacturer will continue monitoring its software repositories and will publish new update logs in its application manager during upcoming scheduled reviews.

No Comments

Leave a Reply

Your email address will not be published. Required fields are marked *