BlocktoBlockto
Security Researchers Recreate Transaction-Tampering Exploit on Older Ledger Hardware Wallet App
TECH

Photo: Illustrative

Security Researchers Recreate Transaction-Tampering Exploit on Older Ledger Hardware Wallet App

A security team at wallet provider OneKey has successfully replicated a previously identified vulnerability affecting an outdated version of Ledger's on-device Ethereum application, though the flaw has already been patched and no user funds were affected.

Laurisa
By Laurisa

Junior Author · August 28, 2026

2 min
Key takeaways
A security team at wallet provider OneKey has successfully replicated a previously identified vulnerability affecting an outdated version of Ledger's on-device Ethereum application, though the flaw has already been patched and no user funds were affected.
How the Exploit Worked The team demonstrated what's known as a transaction replacement attack, in which an outdated app version allowed a transaction waiting for user approval to be secretly swapped with a different one while still appearing legitimate on screen.
Ledger explained that carrying out such an attack would require an attacker to already control communication between the wallet and its connected device, such as through malware or a compromised website.

A security team at wallet provider OneKey has successfully replicated a previously identified vulnerability affecting an outdated version of Ledger’s on-device Ethereum application, though the flaw has already been patched and no user funds were affected.

How the Exploit Worked

The team demonstrated what’s known as a transaction replacement attack, in which an outdated app version allowed a transaction waiting for user approval to be secretly swapped with a different one while still appearing legitimate on screen. Ledger explained that carrying out such an attack would require an attacker to already control communication between the wallet and its connected device, such as through malware or a compromised website.

(Yishi)

Ledger’s Response

The company addressed the issue in two stages, first adding safeguards at the application level in mid August, followed by a deeper fix to its underlying secure software shortly after. Ledger emphasized that the demonstration was conducted only in a controlled lab setting and did not involve any real user being compromised.

Part of a Broader Pattern

This case follows a separate wallet security issue disclosed last month involving a different hardware wallet brand, though the two vulnerabilities stem from unrelated causes one tied to weak randomness in key generation, the other to how transactions are processed during signing.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.

Security Researchers Recreate Transaction-Tampering Exploit on Older Ledger Hardware Wallet App — Blockto - Blockto