By Interestana AI Editorial — AI-drafted, human-overseen. How we report
OneKey Reproduces Transaction Replacement Attack on Ledger

OneKey, a cryptocurrency wallet provider, announced on March 11, 2024, that its security team successfully reproduced a transaction replacement attack within a laboratory setting. This exploit targeted an outdated version of the Ledger Ethereum application. The vulnerability, if exploited in the wild, could have allowed an attacker to replace a legitimate transaction with a fraudulent one, potentially leading to the loss of user funds. However, OneKey emphasized that no user funds were lost as a result of this discovery, and Ledger has already implemented a fix.
The specific attack vector involved a flaw in how the older Ledger Ethereum app handled transaction signing and verification. Transaction replacement attacks, also known as replay attacks in some contexts, exploit weaknesses in the way transactions are broadcast and confirmed on a blockchain. In this instance, an attacker could potentially intercept a user's signed transaction and modify its details before it is confirmed by the network, or replay a previously valid transaction under different circumstances. The effectiveness of such an attack hinges on the specific implementation details of the wallet software and the blockchain protocol.
Ledger, a prominent manufacturer of hardware cryptocurrency wallets, confirmed that the vulnerability was addressed in version 1.22.2 of its Ethereum app. The company stated that the fix was deployed promptly after being notified by OneKey. Ledger's hardware wallets are designed to provide a secure environment for storing private keys, isolated from internet-connected devices, thereby mitigating many common online threats. However, vulnerabilities can still arise in the software interfaces and application layers that interact with the hardware.
OneKey's disclosure highlights the ongoing importance of rigorous security audits and prompt patching of vulnerabilities in the cryptocurrency ecosystem. Hardware wallets like those produced by Ledger are considered a cornerstone of cryptocurrency security for many users, and any potential weakness in their software is of significant concern. The collaboration between security researchers like those at OneKey and wallet manufacturers like Ledger is crucial for maintaining the integrity and safety of digital asset management. This incident serves as a reminder that even established security solutions require continuous vigilance and updates to stay ahead of evolving threats.
Original source — read the full reporting at the publisher:
Read on CoinTelegraphGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.