Crypto Prices

OneKey demonstrates vulnerability in outdated Ledger Ethereum application through controlled test

10 hours ago
1 min read
4 views

Security Analysis of Ledger’s Ethereum Application

In a recent security analysis, OneKey confirmed that it was able to demonstrate a previously identified exploit impacting an older version of Ledger’s Ethereum application, specifically version 1.22.1. This incident occurred in a controlled laboratory setting and did not result in any loss of user funds.

Details of the Exploit

Yishi Wang, the CEO and founder of OneKey, explained that the team conducted a “transaction replacement attack” which capitalized on a vulnerability that had already been addressed in the updated version 1.22.2 of the app, released on August 13.

The nature of this exploit hinges on the ability to manipulate a transaction that is awaiting user approval. The vulnerability allowed attackers to substitute the intended transaction with one of their own while the legitimate transaction was still being reviewed by the user. Reportedly, to exploit this flaw, an attacker would necessitate access to the communication channels between the Ledger device and its connected host. Potential threats, such as malware, compromised wallet applications, or malicious web pages, could allow for such control.

Ledger’s Response

Ledger released a statement clarifying that no users of their devices were compromised during this lab simulation. The company emphasized that the attack described was merely a reproduction of an older flaw in the Ethereum app and not indicative of a direct threat to current Ledger users.

Context of the Vulnerability

This event occurred in the wake of a separate vulnerability discovered in Coldcard wallets earlier this year, where attackers took advantage of a firmware bug that weakened seed randomness, potentially exposing users to brute-force attacks on private keys. However, Ledger maintains that their device architecture, particularly the random phrase generation through a certified security chip, protects their users from such issues. The flaw demonstrated by OneKey notably differs from those concerning key generation, focusing instead on transaction signing procedures.

Popular