security
OneKey Reproduces Transaction Replacement Attack on Older Ledger Version
OneKey has demonstrated a transaction replacement attack on an outdated version of Ledger's Ethereum app, which Ledger addressed in its version 1.22.2, with no user funds lost.
AS1 NewsSource: cointelegraph.com
In a recent security demonstration, OneKey successfully reproduced a transaction replacement attack against an older version of Ledger's Ethereum application. The attack was carried out in a controlled lab environment, highlighting vulnerabilities in previous software versions. Ledger responded by releasing an update to its Ethereum app, version 1.22.2, which fixed the identified security flaw. Importantly, no user funds were compromised during this process, indicating that the vulnerability was effectively mitigated through the update. This incident underscores the importance of keeping hardware wallet firmware up to date to protect against potential exploits. Security researchers continue to scrutinize hardware wallet software to ensure the safety of user assets amid evolving attack techniques.
The demonstration highlights the importance of firmware updates for hardware wallets to prevent transaction replacement attacks.