
The OneKey Anzen research team has identified a critical security flaw in Ledger hardware wallets that allows transaction manipulation at the cryptographic signing stage. The discovery was publicly announced by OneKey founder and CEO Ishi Wang, who described the situation with the phrase "we hacked Ledger." The vulnerability affected the dedicated Ethereum network application built into devices made by the French manufacturer.
The core of the identified flaw lay in a desynchronization between the visual information displayed on the device screen and the internal data processing. This peculiarity created a time window during which a third party could modify transaction parameters after they had already been shown to the user but before the digital signature was actually applied. As a result, the wallet owner could visually verify and approve one set of transfer details, while the device cryptographically finalized an entirely different transaction.
The research team successfully reproduced the full exploitation scenario in a controlled test environment. The attack process involved several sequential steps: the user viewed transaction parameters on the Ledger display, verified the data, and initiated the confirmation procedure. At that intermediate moment, the attacker swapped the original parameters for modified ones, after which the hardware device completed the signing of the altered transaction that the wallet holder had never actually seen or approved.
The technical issue was traced to the Ethereum app for Ledger version 1.22.1. The hardware wallet manufacturer responded promptly to the vulnerability disclosure and released a corrective update, version 1.22.3, which fully addressed the security flaw. Representatives of the research team strongly urge all users still running outdated versions of the software to install the latest build immediately in order to protect their digital assets from potential manipulation.
This incident is the latest in a series of hardware wallet security events in recent times. Previously, an X user known by the pseudonym x3ideRaven reported receiving a phishing message impersonating official communication from competing manufacturer Trezor.
