Crypto wallet maker OneKey and cybersecurity firm Anzen claim to have reproduced a transaction replacement attack on Ledger’s Ethereum app version 1.22.1. Ledger disputes this, stating that the vulnerability had already been patched in version 1.22.3 released in August, and that no user was hacked. Ledger’s CTO Charles Guillemet characterized the demonstration as a lab exercise rather than a genuine security finding. OneKey had previously warned users of Ledger’s older Ethereum app to update it.
Source: Read the original article

