Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
- OneKey said it reproduced a Transaction Replacement Attack vulnerability in an older Ledger Ethereum (ETH) application.
- The company said the flaw created a risk that a pending transaction could be replaced with another one, sending assets to an attacker-controlled address.
- Ledger said it fixed the issue through Ethereum app version 1.22.2 and Secure SDK 26.6.1, and that no hacking cases had occurred.
Forecast Trend Report by Period
Hardware wallet maker OneKey has recreated a vulnerability in an older Ledger Ethereum app that could allow an attacker to replace a transaction a user intended to sign with a different one. The flaw has since been fixed.
Cointelegraph reported on August 28 that OneKey’s security team successfully reproduced a “Transaction Replacement Attack” in its own test environment using version 1.22.1 of Ledger’s Ethereum app.
In this type of attack, an attacker swaps out a pending transaction while the user is reviewing what appears to be legitimate transaction details on the hardware wallet screen. That means the transaction ultimately signed could differ from the one the user first verified, creating a risk that assets could be sent to an address designated by the attacker.
Ledger released version 1.22.2 of its Ethereum app on August 13, adding app-level safeguards. On August 21, it also fixed the underlying issue through Secure SDK 26.6.1.
“No Ledger users have been hacked,” the company said. The incident involved a vulnerability in an older version of the Ethereum app that was reproduced in a lab environment, it added.
Source: en.bloomingbit.io
