arrow back

Ledger Under Pressure Over Ethereum App Vulnerability

28 Aug 2026

Ledger Under Pressure Over Ethereum App Vulnerability

OneKey Anzen said it had found a vulnerability in Ledger Ethereum app 1.22.1 that allowed a transaction to be swapped during signing. This affects hardware wallet owners who work with Ethereum every day. The situation is simple and unpleasant.

According to OneKey founder and CEO Ishi Wan, the team reproduced the attack in a lab. The user saw transaction A, confirmed it, but actually signed transaction B. The issue has already been fixed in version 1.22.3. Older versions are recommended to be updated.

Ledger disagrees with the wording about a “Ledger hack.” In Decrypt, the company explained that this was a fixed bug in an old version of the Ethereum app, not a compromise of the devices themselves. According to Ledger, there have been no confirmed user hacks or fund losses.

What exactly was found in Ledger?

The core of the problem is the gap between what the screen shows and what the device actually signs. In short, an attacker could swap the data after it appeared on the screen but before the signing moment. This is the worst-case scenario for a hardware wallet.

Ledger’s official classification for this case is LSB 023 and CWE-362. The Ledger Donjon page states that this involves command interleaving, meaning the ability to send a new APDU command while reviewing a previous operation. The flaw was not in the device OS, but in the Ledger Secure SDK.

This is an important detail. It means the risk depended on the app version, not just on owning a Ledger. That is why updating here is critical. And for those who want to sell Ethereum ETH on Monobank, this is another reason not to delay checking the wallet version.

Why does this matter for Ethereum users?

Because signing in a wallet should be the final point of control. If one thing is shown on the screen and another is signed, the purpose of a hardware wallet is partly lost. That is why stories like this spread quickly through the crypto community.

Ledger says the attack required control over the communication channel with the device. This could be a malicious or compromised wallet app, a hostile WebHID/WebUSB page, or malware on the computer. The seed phrase and private keys were not extracted in the process.

There is also a broader context. Ledger says it has sold more than 7 million devices, has customers in 180 countries, and works with 100+ resellers. So even one bug in an app has major repercussions. And not only among traders, but also among long-term ETH holders.

Market reaction and Ledger’s position

Ishi Wan wrote on X: “We hacked ledger.” That phrase is what triggered the wave of discussion. But Ledger publicly narrowed the scope of the issue to a now-closed vulnerability in an outdated version of the Ethereum app.

Ledger emphasizes that this was a laboratory reproduction of an old bug, not a hack of users’ devices.

In the company’s technical bulletin, it also showed the timeline of fixes. The regression was introduced back in August 2025. The SDK fix was written on June 8, 2026. Version v26.6.0 was released on August 11, Ethereum app 1.22.2 with the first protections appeared on August 13, and Secure SDK v26.6.1 was released on August 21, 2026.

Ledger also published three security bulletins on August 27. In addition to LSB 023, there are also LSB 024 and LSB 025. This is no longer a single minor glitch, but a series of issues the company is addressing publicly and step by step.

  • The issue affected Ethereum app 1.22.1.

  • Ledger fixed it in version 1.22.3.

  • The attack required control over the communication channel with the device.

  • The seed phrase and private keys were not compromised.

  • Ledger did not confirm any user fund losses.

  • Separately, Ledger acknowledged two more incidents in bulletins 024 and 025.

What does this mean for investors?

For ETH holders and those who sign transactions often, the takeaway is simple: you need to check not only the device, but also the app version. Ledger says directly that a firmware update alone does not close the risk if the app is built on an old SDK.

In practical terms, this means three things. First, update apps through Ledger Live. Second, check the version on the signer device itself. Third, do not sign operations from suspicious sites or a compromised computer.

There is one more important nuance. The vulnerability did not extract keys, but it could swap the transaction content. For DeFi users, this is especially painful, because one signing mistake can change not only the amount, but also the address or the type of operation.

Against this backdrop, the story about a phishing email disguised as Trezor, previously discussed on X, is a reminder of a simple fact: attacks often target not the hardware, but the user’s trust. And here, vigilance matters no less than the wallet brand.

Frequently asked questions

Was Ledger really hacked?

Ledger says no. The company describes this as a lab-reproduced bug in an old version of the Ethereum app that has already been fixed. According to Ledger, there have been no confirmed user hacks or fund losses.

Which versions were at risk?

According to Ledger Donjon, the issue affected Ethereum app 1.22.1, while the broader LSB 024 description covers versions 1.19.0–1.22.2 for a separate bypass scenario. The company recommends updating to 1.22.3 and checking the app version manually.

What should Ledger owners do right now?

Update apps through Ledger Live, check the Ethereum app version, and do not sign questionable transactions from an unverified computer. If you work with ETH often, it is better to double-check the address and amount before confirming.

This story is not about panic, but about the habit of checking versions and the source of a transaction. For those who want to quickly sell Ethereum ETH on Monobank, attention to security is now no less important than the exchange rate.

This material is not financial advice. Cryptocurrency trading involves significant risks. Part of this text was prepared with the help of artificial intelligence based on public sources and reviewed by our editorial team.