My analytical team and I are closely monitoring the latest developments in the field of hardware wallet security. This time, the spotlight is on a serious finding related to Ledger.

The essence of the discovered issue

A group of researchers from OneKey Anzen managed to reproduce a transaction substitution attack in the laboratory on the Ethereum application of the Ledger wallet version 1.22.1. This is a classic race condition scenario — a state of competition arising between the logic of displaying data on the device screen and its internal buffer. As a result, the hardware wallet may show the user one transaction for confirmation, while in reality signing a completely different one.

Technically, the attack is based on sending a new APDU command at the moment when the device owner is still only confirming the previous operation on the screen. This vector allows an attacker to manipulate the data flow, misleading the victim about what exactly they are authorizing.

Ledger's response and fix status

The Ledger Donjon security team promptly confirmed the existence of the vulnerability. It is important to emphasize that the issue has already been fixed in update 1.22.2, released on August 13. According to official statements, no real user was affected — all tests were conducted exclusively in a controlled environment, and the vulnerability itself was discovered during an internal security review process.

The company emphasizes that the described scenario applies to an outdated version of the application, and the released patch fully closes this vector. Nevertheless, Ledger strongly recommends that all device owners update their software and check the relevance of the hardware firmware.

Context and conclusions

This finding is not an isolated case. I recall that on August 17, the hardware wallet manufacturer BitBox also released the Dixence update, closing two serious vulnerabilities discovered during internal audits using AI models. This confirms a trend: the hardware security industry is moving toward more proactive bug hunting, and such laboratory research is a normal stage of evolution.

My expert opinion: although the incident did not lead to loss of funds, it serves as an important reminder that even the most reliable hardware wallets are not immune to software errors. Investors should develop a habit of regularly updating firmware and applications, as well as checking recipient addresses on the device itself, not just on the computer screen. Security is a process, not a static state.