In laboratory conditions, the OneKey Anzen team managed to reproduce a complex transaction substitution attack against the Ethereum application of the Ledger hardware wallet version 1.22.1. This is a rare case where researchers demonstrate the exploitation of a race condition in a critical security component.
The essence of the vulnerability lies in a conflict between the transaction display logic and the underlying data buffer. At the moment when the user sees one operation on the device screen and confirms it, an attacker can send a new APDU command that replaces the data in the buffer. As a result, the hardware wallet signs a completely different transaction than the one approved by the owner. This attack vector is especially dangerous because it undermines the very trust in hardware security measures, which are considered the "gold standard" in the industry.
The Ledger Donjon security team promptly confirmed the issue but emphasized that no real user was affected. The scenario remained strictly laboratory-based, and the vulnerability was localized to an outdated version of the application. A patch fixing the bug was released on August 13 in version 1.22.2 — even before the researchers' public disclosure.
In the official Ledger security bulletin, it is noted that the issue affected only the transaction confirmation process when sending new commands. The company strongly recommends that all device owners update the software and check the relevance of the hardware firmware. This is a standard but critically important procedure that many users, unfortunately, ignore.
It is worth recalling that on August 17, the manufacturer BitBox also released the Dixence update, closing two serious vulnerabilities in the firmware of its wallets. The errors were discovered during internal audits using AI models, which indicates the growing role of automated tools in vulnerability discovery.
My analysis: This incident is a vivid reminder that even the most protected hardware solutions are not an absolute panacea. Race conditions are a class of errors that are difficult to identify during traditional testing, and their presence in the Ledger Ethereum application indicates the need for deeper code auditing at the firmware level. The industry is moving toward zero tolerance for such bugs, and I expect that in the near future we will see stricter security standards for all hardware wallet manufacturers.