Two hardware wallet makers are now trading barbs after OneKey’s security team said it managed to reproduce an exploit in an old version of Ledger’s Ethereum app, and Ledger fired back over how that claim got framed.OneKey founder and CEO Yishi Wang posted that his company’s Anzen security team pulled off what he called a transaction replacement attack against Ledger’s Ethereum app version 1.22.1, inside a controlled lab environment. He pinned the flaw on a race condition, a timing gap between the app’s transaction display and the buffer holding the actual transaction data. In practice, that gap could let someone swap a legitimate transaction for a malicious one while the original still showed on screen, mid-review. However, it only worked if a user was actively approving a transaction at the precise moment malicious code was tampering with the pending signing context.Wang didn’t hold back describing the result, writing “we hacked Ledger” on X and noting the bug had since been closed in Ethereum app 1.22.3. Ledger CTO Charles Guillemet wasn’t having it. He said reproducing a bug that’s already been patched isn’t “hacking Ledger,” and called OneKey’s demo a lab exercise run against an outdated app rather than anything current users needed to worry about.Ledger’s own breakdown fills in more of the technical picture. The company traced the root defect to input and output handling inside its Secure SDK, not the device’s operating system or firmware. Apps built on the flawed SDK versions leaned on their own internal state checks to block commands arriving mid-review, so exposure came down to how well each app implemented that check. Get it right, and the app stayed safe even on the vulnerable SDK.Version history backs up a tighter timeline than the “we hacked Ledger” framing suggests. Ethereum app 1.22.2, out August 13, was the first release with state checks built to shut down this exact substitution path. Ledger followed on August 21 with Secure SDK 26.6.1, a deeper fix that stops interleaved commands before they even reach app code. Developers rebuilt on top of that. Ledger’s current guidance points users toward Ethereum app 1.22.3 or later, since it bundles the full SDK protection plus a fix for a separate display bug. So OneKey wasn’t wrong that 1.22.3 is safe, Ledger just notes the first real fix landed a version earlier.Pulling off the exploit required more than proximity to the device. Ledger said an attacker needed control over the line between the wallet and its host, via malware, compromised wallet software, or a rigged webpage. The company also said it’s seen no sign anyone exploited the bug, internally tracked as LSB 023, against actual customers, and no losses have surfaced tied to it.Ledger in a Thursday post on X, said, “No Ledger user was hacked. What’s described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app.”Ledger has advised users to open Ledger Live, install the latest device apps, and confirm the Ethereum app version on the hardware wallet directly. A firmware update alone won’t cut it, apps built on the flawed SDK need replacing too. Ledger is also pushing third-party developers to audit their own state handling and rebuild against Secure SDK 26.6.1 or newer. The company dates the original weakness to August 2025, spanning SDK versions up through 26.6.0.The dust-up lands not long after a separate scare hit the hardware wallet world. In July, attackers went after a firmware bug in certain Coldcard devices, one dating back to March 2021, that weakened seed-phrase randomness and left private keys open to brute-force attacks. Ledger had already said its own devices dodged that issue, since its recovery phrases come from a certified randomness source baked into the device’s security chip. South Africa’s FSCA Goes on Crypto Exchange Licensing SpreeFriesDAO Raises $5.4 Million, Takes Hospitality to a New Level in CryptoNew Malware that Exploits Crypto Wallets has been DiscoveredUnizen x GEC to Launch the DOGE-1 Space Mission with SpaceX