The analytical group OneKey Anzen, during laboratory tests, successfully reproduced a critical transaction substitution attack in the Ethereum application of the Ledger hardware wallet version 1.22.1. This discovery sheds light on the hidden risks that even users of the most secure devices may face.
The Essence of the Problem: A Race Condition in a Critical Component
The detected bug lies in a so-called race condition between the logic for displaying transaction data and the device's underlying buffer. In a practical scenario, this means that an attacker can send a new APDU command at the moment when the wallet owner is still confirming a previous operation on the screen. As a result, the user sees one amount or recipient address but signs a completely different transaction. This is a classic attack on trust in the hardware interface, undermining the very concept of "what you see is what you sign."
Ledger's Response and Fix Status
Specialists from Ledger's internal security team, Ledger Donjon, promptly confirmed the presence of the vulnerability. It is important to emphasize that the issue had already been resolved in patch 1.22.2, released back on August 13—two weeks before the public disclosure. According to official statements, no real user was affected, and the attack remained exclusively a laboratory scenario reproduced on an outdated version of the software.
In the official security bulletin, the company strongly recommends that all device owners update the Ethereum application to the latest version and check the freshness of the hardware firmware. This is a standard but critically important procedure that many users tend to ignore, relying on the "impregnability" of hardware wallets.
Industry Context: Systemic Challenges
This incident is not an isolated case. Just a few days earlier, on August 17, the hardware wallet manufacturer BitBox released the Dixence update, closing two serious firmware vulnerabilities discovered during internal audits using AI models. The industry is clearly entering a new phase where even the most secure devices require constant firmware and application updates.
My comment: This case is a vivid reminder that hardware security is not static. Even in the absence of real victims, such findings demonstrate that the arms race between researchers and developers never stops. Investors and holders of crypto assets should view regular updates not as an option but as a mandatory element of security hygiene, especially amid the growing complexity of attacks at the protocol and application levels.