FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.6T +1.1%24h Vol $62.4B +18%Fear & Greed 57/100Alts Index 31/100
BTC.D 59.0% 0%Stable.D 10.0% -0.1%ETH.D 11.6% 0%Others.D 19.4% +0.1%
FIL$0.9963+22.47%BTW$0.6373+15.22%ZCAT$0.0961+11.41%龙虾$0.1492+10.06%AR$2.807+9.59%LIT$4.555+9.37%EDGE$0.6420+8.15%CRV$0.3610+7.11%ANTFUN$0.0842+5.65%NOCK$0.0471+5.55%
UAI$0.5143-35.35%LSK$0.6199-30.7%AI$0.2490-27.54%MARSCOIN$0.0934-22.15%MINA$0.0877-19.26%LAPTOP$0.2994-18.09%CASHCAT$0.1517-13.24%MET$0.2214-11.25%STONK$0.2623-11.11%RAY$1.417-10.05%
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      OneKey Demonstrates Transaction Replacement Attack on Ledger Ethereum Application

      OneKey's security team has successfully replicated a vulnerability in the old version of the Ledger Ethereum application, specifically version 1.22.1. The demonstration involved executing a transaction replacement attack, which allowed the team to overwrite pending transactions while users were reviewing legitimate ones. This vulnerability was previously patched, but OneKey's founder and CEO, Wang Yishi, confirmed that it could still be exploited under certain conditions.

      Ledger has responded to the findings, stating that exploiting this vulnerability requires control over the communication between the device and the host, which could be achieved through malware, compromised wallet software, or malicious web pages. The company released an updated version of the Ethereum application, version 1.22.2, on August 13, which includes application layer protections, and addressed the underlying issue in Secure SDK 26.6.1 on August 21.

      Ledger emphasized that no users were hacked as a result of this replication, clarifying that it was conducted in a controlled laboratory environment. This incident follows a recent vulnerability found in the Coldcard wallet, which raised concerns about mnemonic phrase generation. However, Ledger assured that its devices were not affected by that issue, as recovery phrases are generated by a certified random source within the device's secure chip. The vulnerability replicated by OneKey pertains specifically to transaction processing during the signing process.

      © 2026 KLEA News. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

      Source: KLEA News

      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud