Ledger Disputes OneKey’s Claim of Hacking Patched Ethereum App

OneKey and Anzen claim to have hacked an older version of Ledger's Ethereum app, but Ledger says the bug was already patched and no users were affected.

28/08/2026 07:184 min read

OneKey and cybersecurity outfit Anzen say they found a way to hack version 1.22.1 of Ledger's Ethereum application. Ledger strongly contests this, stating, "No Ledger user was hacked."

Earlier in the day, OneKey co-founder Yishi Wang explained on X how his security team managed to replicate a transaction replacement attack that occurs when a user is examining a genuine transaction.

Wang stated, "We hacked ledger," and urged users of Ledger's outdated Ethereum app to upgrade, pointing out that Ledger had already patched the issue in version 1.22.3.

Ledger Argues OneKey Did Not Hack Anything

A few hours later, Ledger CTO Charles Guillemet replied, asserting that "reproducing an already-patched bug is not 'hacking Ledger.'"

He further said, "No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding."

A representative for Ledger told Protos that OneKey "took the already disclosed findings and tried to replicate them in a lab environment."

According to the Ledger Donjon team, the update was released on August 13 in version 1.22.2, which further disputes OneKey's assertions.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles