OneKey Reproduces Transaction Replacement Attack on Old Version of Ledger
7 Articles
7 Articles
OneKey Reproduces Transaction Replacement Attack on Old Version of Ledger
OneKey said it executed a “transaction replacement attack” against an older version of Ledger, but the wallet provider had already fixed the vulnerability in a previous upgrade.
Ledger says the viral “hack” was already patched, but two real bugs still needed fixing
Crypto wallet maker Ledger is urging its Ethereum app users to update again after two signing flaws remained in its previous security release. The hardware-wallet maker published Ethereum app version 1.22.3 on Aug. 25, closing vulnerabilities that could hide operations from a device review or authorize a token approval in place of an expected payment. The update follows controversy over a separate Ethereum signing flaw reproduced by rival wallet…
OneKey recreates patched Ledger vulnerability - CoinCodeCap
Two hardware wallet makers are now trading barbs after OneKey’s security team said it managed to reproduce an exploit in an old version of Ledger’s Ethereum app, and Ledger fired back over how that claim got framed. OneKey founder and CEO Yishi Wang posted that his company’s Anzen security team pulled off what he called a transaction replacement attack against Ledger’s Ethereum app version 1.22.1, inside a controlled lab environment. He pinned t…
Ledger закрыл уязвимость с подменой транзакций в Ethereum-приложении
Команда OneKey Anzen смогла воспроизвести в тестовых условиях атаку подмены транзакции в Ethereum-приложении кошелька Ledger версии 1.22.1. we hacked ledger.the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab.the bug i...
OneKey Says It Hacked Ledger; Ledger Says 1.22.3 Fixed It
Hardware wallet maker OneKey says its security researchers successfully reproduced a transaction-replacement attack against Ledger, demonstrating a vulnerability that could cause a device to sign a different Ethereum transaction from the one displayed to its owner. OneKey founder and CEO Yishi Wang disclosed the laboratory test on August 27, saying the company’s Anzen security team successfully reproduced the attack against Ledger Ethereum app v…
ChainCatcher reports that Ledger disclosed details of the LSB 023 security vulnerability on its official website yesterday. Some applications built on the Ledger Secure SDK may still receive new APDU commands during user screen confirmation, causing inconsistencies between the parameters displayed on the screen and the final signature parameters. In the event that an attacker controls the APDU communication between the device and the host, the d…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium







