Bitcoin Forum
August 30, 2026, 01:20:39 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Ledger hacked or vulnerable  (Read 133 times)
dkbit98 (OP)
Legendary
*
Offline

Activity: 3066
Merit: 8839



View Profile WWW
August 27, 2026, 08:33:53 PM
 #1

Chinese team OneKey_Anzen published a report claiming they exploied ledger vulnerability,
and they successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1.
I never liked ledger apps, especially for altcoins, and they are clearly another weak spot in bad closed source space.
It is good to see Onekey developers are actually doing some investigation.
https://x.com/ohyishi/status/2092953186193801599
https://onekey.so/anzen/

Ledger already replied they fixed this and there are no evidence of attacks happened against users.
There are 3 security bulletin reports from today and you can read their explanation:
https://donjon.ledger.com/lsb/

Even if people didn't lose coins with ledger, and I again suggesting everyone to STOP using this devices.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
Charles-Tim
Legendary
*
Offline

Activity: 2380
Merit: 6519


Leading Crypto Sports Betting & Casino Platform


View Profile
August 27, 2026, 08:39:44 PM
 #2

I read about it today, it was about something related to ethereum. Ledger said it fixed it in version 1.22.2 before OneKey reported the vulnerability. That was what Ledger said about it.

But there are people that would have not updated their wallet.

Ledger has been one of the hardware wallets that I do not like since I join this forum because of the hardware wallet secure element.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Mia Chloe
Legendary
*
Offline

Activity: 1176
Merit: 2287


Contact me for your designs...


View Profile
August 27, 2026, 09:20:19 PM
 #3

~snip
I think the vulnerability is definitely concerning but I wouldn't go as far as saying everyone should stop using Ledger based on this alone however I personally don't recommend using it in the first place.

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited. Anyways for me the bigger concern is the closed source nature of some of their software that alone is enough to make me prefer more transparent alternatives  the idea of closes source for a hardware wallet kinda sounds unsafe to me.

X-ray
Hero Member
*****
Offline

Activity: 3710
Merit: 567


Leading Crypto Sports Betting & Casino Platform


View Profile
August 28, 2026, 04:00:37 AM
 #4

~snip
I think the vulnerability is definitely concerning but I wouldn't go as far as saying everyone should stop using Ledger based on this alone however I personally don't recommend using it in the first place.

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited. Anyways for me the bigger concern is the closed source nature of some of their software that alone is enough to make me prefer more transparent alternatives  the idea of closes source for a hardware wallet kinda sounds unsafe to me.
The OneKey team reproduced by building 1.22.1 ELF, a firmware that have the vulnerability after the fix has been live, but I think it's kind of pointless?

The team said they hacked the ledger but in reality they're only building old vulnerable firmware with disclosed vulnerability.

The reproduction of transaction was to show that the race condition is really there but the fact that ledger team released fix means it's there without even the need to reproduce the attack.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
joniboini
Legendary
*
Offline

Activity: 3024
Merit: 1921



View Profile WWW
August 28, 2026, 04:25:03 AM
 #5

The OneKey team reproduced by building 1.22.1 ELF, a firmware that have the vulnerability after the fix has been live, but I think it's kind of pointless?
I wonder if scammers will go out of their way to distribute this vulnerable firmware with DNS attack or something similar. Based on some recent supply chain attacks it's possible they'll upload malicious files and users will get tricked thinking it's a valid update. That being said though, if that's in their plan they'll probably went as far as uploading malware instead of vulnerable firmware that requires a trick or two to exploit. CMIIW.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
satscraper
Legendary
*
Offline

Activity: 1568
Merit: 2913



View Profile
August 28, 2026, 06:22:05 AM
Last edit: August 28, 2026, 06:56:34 AM by satscraper
 #6

I read about it today, it was about something related to ethereum. Ledger said it fixed it in version 1.22.2 before OneKey reported the vulnerability. That was what Ledger said about it.



The ethereum app was just the first one patched,  but according to  Bulletin 023 the underlying flaw lived in shared SDK code that every app built on, not something specific exclusively to Ethereum. Ledger fixed this releasing new SDK v26.6.1, released 21 August so now the 3rd party app developers who are relevant to Ledger must react and rebuild to be on the safe side.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
Synchronice
Legendary
*
Offline

Activity: 1694
Merit: 1185



View Profile
August 28, 2026, 10:20:22 AM
 #7

~snip
I think the vulnerability is definitely concerning but I wouldn't go as far as saying everyone should stop using Ledger based on this alone however I personally don't recommend using it in the first place.

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited. Anyways for me the bigger concern is the closed source nature of some of their software that alone is enough to make me prefer more transparent alternatives  the idea of closes source for a hardware wallet kinda sounds unsafe to me.
This vulnerability alone is not the reason why people should stop using Ledger. First of all, Ledger is partially open source but its core firmware tied to secure chip remains closed source and here is the most important part, Ledger has been lying to us that keys never leave Secure Chip. Later, they introduced Ledger Recover service, which made it clear that keys leave Secure Chip. So, basically, the most important part of their code is closed-source and they also lie to us. Basically, we don't know the code and they don't tell the truth, so it's a big no.

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████▀█▀████████████████▀████████████████▀█████████████████████████████▀████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████████████████████████▀██████▀█████▀████████▀█████
██████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████▄█▄████████████████▄████████████████▄█████████████████████████████████▄██████▄█████▄████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
 🍒   ⚽️    IIIIIFASTEST GROWING CASINO & SPORTSBOOK     Play Now    
_act_
Legendary
*
Offline

Activity: 1722
Merit: 1984



View Profile
August 28, 2026, 01:28:30 PM
 #8

This vulnerability alone is not the reason why people should stop using Ledger. First of all, Ledger is partially open source but its core firmware tied to secure chip remains closed source and here is the most important part, Ledger has been lying to us that keys never leave Secure Chip. Later, they introduced Ledger Recover service, which made it clear that keys leave Secure Chip. So, basically, the most important part of their code is closed-source and they also lie to us. Basically, we don't know the code and they don't tell the truth, so it's a big no.
Ledger also said the seed phrase sent to the recovery services can be given to the government if the government demanded for it. That means the coins people have on ledger, they do not have full control over it. People will always be people, they supposed to all stop using Ledger after doing all these.

When talking about privacy, Ledger is the worst that you can use. Scammers and hackers may know that you are using Ledger. But this is becoming common to other wallets.

stompix
Legendary
*
Offline

Activity: 3724
Merit: 7315



View Profile WWW
August 28, 2026, 02:57:01 PM
 #9

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited.

Someone managing to exploit a piece of software in a controlled environment doesn't mean that all the devices are vulnerable.
You still needed to have access to that device to run it, so either infect the device itself, or do so through an infected computer with specifically that kind of malware....
This is an incredibly small pool of attacks, you need to target Ledger users, Ledger users with said coin balance, be able to infect their computer point of entry or one of the apps, wait for them to actually make a transaction before they update their devices.
The moment you're able to do that you have a lot more options than just this exploit to drain a balance.





▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Yamane_Keto
Hero Member
*****
Offline

Activity: 966
Merit: 601



View Profile WWW
August 28, 2026, 05:10:58 PM
 #10

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited.
For these attacks to succeed, the user must either download a malicious wallet application, establish a WebUSB connection, or install malware on their computer; this implies that success relies on user negligence rather than a device failure. yet exploiting these bugs remains difficult.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
X-ray
Hero Member
*****
Offline

Activity: 3710
Merit: 567


Leading Crypto Sports Betting & Casino Platform


View Profile
August 29, 2026, 01:19:29 AM
 #11

I wonder if scammers will go out of their way to distribute this vulnerable firmware with DNS attack or something similar. Based on some recent supply chain attacks it's possible they'll upload malicious files and users will get tricked thinking it's a valid update. That being said though, if that's in their plan they'll probably went as far as uploading malware instead of vulnerable firmware that requires a trick or two to exploit. CMIIW.
I doubt it's going to be that easy, the Ethereum app (1.22.1) build isn't going to be officially signed.

If I read correctly, the OneKey team only using Ledger's emulator Speculos to run the build and recreate or reproduce the attack.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!