Ledger Ethereum App Flaw: Patched in v1.22.2 on Aug 13, Company Says
OneKey says it reproduced a transaction-swap bug in Ledger's Ethereum app v1.22.1. Ledger says the fix shipped weeks earlier.

Two version numbers, one disputed timeline. Wallet maker OneKey says its security unit Anzen reproduced a transaction-replacement bug in Ledger’s Ethereum app version 1.22.1, letting a compromised app sign a different transaction than the one shown on the device screen. Ledger says the same flaw was already patched, in version 1.22.2, shipped on August 13. Both companies agree on one thing: no user funds were actually taken.
The dispute surfaced on August 27, when OneKey founder Yishi Wang published details of the exploit and wrote, “We hacked ledger.” Ledger’s response came the same day. This is a two-sided public exchange, not a leaked internal memo or an anonymous tip. Both statements carry named attribution: Wang for OneKey, CTO Charles Guillemet and a company spokesperson for Ledger.
What OneKey Demonstrated
Anzen’s demo targeted a scenario familiar to hardware-wallet users: reviewing a legitimate transaction on the device before signing. In the outdated app, the team says it could substitute a different transaction during that review window. Wang urged anyone still running Ledger’s older Ethereum app to update immediately, framing it as a live risk for laggard users rather than a current one for patched wallets.
Ledger’s Counter: A Lab Exercise, Not a Finding
Guillemet rejected the framing outright. “Reproducing an already-patched bug is not ‘hacking Ledger,'” he said. He added a sharper line: “No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding.”
A Ledger spokesperson gave a more clinical account to Protos, saying OneKey “took the already disclosed findings and tried to replicate them in a lab environment.” That statement implies Ledger’s own Donjon security team had already disclosed the underlying issue before OneKey’s post. Ledger points to version 1.22.2, released August 13, as the fix.
The Version-Number Gap Nobody Has Reconciled
Here is where the two accounts stop lining up cleanly. Ledger’s Donjon team cites 1.22.2 as the patched release. Reporting on OneKey’s side references 1.22.3 as the version where the issue no longer reproduces. That is a one-version discrepancy, unexplained by either side in what has been published so far.
It could be a rounding error in how each company describes its own release history. It could also mean an intermediate patch attempt existed between the two builds. Neither outlet covering this dispute has independently confirmed changelog details for 1.22.2 versus 1.22.3, so that gap remains a single-sourced detail on each side rather than a verified fact.
What is confirmed by both companies’ own statements: no user reported a loss, no exploitation in live wallets has been claimed by either party, and the underlying disclosure predates OneKey’s public demonstration. The disagreement is narrower than “hacked or not.” It is about whether reproducing a fixed bug in a lab counts as new research or as recycled disclosure with a louder headline attached.
Sources
Related articles
Bitcoin at $77,263, Ether at $2,512.60 as Traders Parse Mixed Inflation Print
BTC and ETH both rose after inflation held at 3.4% annually, with core prices cooling yearly but hot monthly, ahead of the…
Trezor’s Email Provider Breached, Fake STM32 Vulnerability Alert Sent to Users
Trezor confirms a third-party email vendor was breached, sending a fake STM32 vulnerability warning; two independent sources verify the incident.
Bitwise Amends Spot Ethereum ETF Filing to Add Staking, Slashing Language
Bitwise's amended S-1 for its spot Ethereum ETF adds staking and slashing-risk language, per one report. The SEC has not approved ETF…