Hardware wallet manufacturer Ledger has firmly denied that any users were hacked after security researchers from rival firm OneKey demonstrated a vulnerability in an outdated version of its Ethereum application. The vulnerability, which affected version 1.22.1 of the Ethereum app for Ledger, allowed a race condition that could replace transactions before signing, potentially redirecting funds to external wallets without the modification appearing on the physical device's screen.
OneKey CEO Yishi Wang stated that the weakness stemmed from a race condition between the data buffer and the device's visual interface. An attacker with control over the intermediary software could overwrite a transaction while the user was reviewing what appeared to be the legitimate operation on screen. The researchers reproduced the attack in a lab setting, publishing technical data that outlined how the vector could function.
Ledger's Chief Technology Officer, Charles Guillemet, immediately rejected the narrative of a security breach. The company clarified that the issue was already identified through its internal security process and fixed in Ethereum app version 1.22.2, released on August 13, 2026, before the public disclosure. The manufacturer published its official security bulletin on August 27, 2026, confirming the absence of active exploits in real-world environments.
Key timeline details: The initial flaw was patched on August 13, 2026, in version 1.22.2. The development team then updated its Secure SDK to version 26.6.1 on August 21, 2026, rebuilding the entire application catalog to prevent similar vectors across other digital assets. The technical report emphasized that an attack of this nature required the host computer to be previously compromised by malware or connected to a malicious web platform, and that private keys stored in the hardware's secure element were never exposed.
Ledger's statement asserted that reproducing a bug on an obsolete version within a lab does not constitute an active vulnerability or a compromise of user funds. The company urged users to verify in Ledger Live that their Ethereum app is updated to version 1.22.3 or higher. The Ledger Donjon security research team noted that the incident highlights the importance of regular update practices for cold wallets, emphasizing that the modular hardware architecture allows patches to be applied to peripheral software without compromising the original recovery seed.
The episode serves as a reminder that wallet firmware and application-level software remain the primary attack surface for hardware wallet users, rather than the blockchain networks themselves. For holders of Ethereum and compatible tokens secured on Ledger devices, the practical takeaway is to keep firmware and coin-specific applications current, as the security promise of a hardware wallet depends on timely software updates.