OneKey announced it successfully reproduced a transaction replacement attack against an outdated version of Ledger’s Ethereum application in a test environment. The exploit targeted version 1.22.1 of the application, which had a vulnerability allowing attackers to replace a transaction pending signature while the user was reviewing it. Ledger fixed the flaw at the application level with version 1.22.2 released on August 13, before resolving the underlying issue in Secure SDK 26.6.1 on August 21. No user funds were lost and Ledger confirmed no users were hacked.
Source: Read the original article

