OneKey reproduces transaction replacement attack on old version of Ledger
The in-house security team at open-source wallet provider OneKey said it successfully reproduced an exploit targeting an outdated version of Ledger’s on-device Ethereum application in a test environment.
Ledger said exploiting the vulnerability required control over communications between the device and its host, such as through malware, compromised wallet software or a hostile webpage. Ledger added app-level safeguards with Ethereum app 1.22.2 released on Aug. 13, before fixing the underlying issue in Secure SDK 26.6.1 on Aug. 21.
The security test follows the Coldcard exploit in July, when attackers exploited a firmware bug introduced in March 2021 that weakened seed randomness on some Coldcard wallets, leaving the resulting private keys vulnerable to brute-force attacks.
The vulnerability reproduced by OneKey is unrelated to seed generation and instead affects how transactions are handled during the signing process.
Magazine: Inside the ‘fake police raid’ that forced a $1M Bitcoin transfer
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Bitcoin Warning from Cryptocurrency Trading Company QCP Capital: “If This Happens, the Rally Will End!” Here Are the Details
JPMorgan Adjusts Price Target on Workday to $225 From $190, Maintains Overweight Rating
KeyBanc Adjusts Price Target on Workday to $215 From $158, Maintains Overweight Rating
Market Chatter: Qualcomm Urged by Vietnam to Expand AI, Chip Investments
