OneKey and cybersecurity firm Anzen claim to have reproduced a transaction replacement attack on Ledger’s Ethereum app version 1.22.1. Ledger firmly denies this, stating no user was hacked and the vulnerability was already patched on August 13 in version 1.22.2. CTO Charles Guillemet described the reproduction as a « lab exercise » rather than a security finding. OneKey nonetheless advises users of the older app to update to version 1.22.3. The dispute centers on what constitutes « hacking. »
Source: Read the original article

