Bitcoin Forum
August 29, 2026, 04:06:04 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: OneKey Team Breaks Ledger in Lab test  (Read 70 times)
cryptomaniac_xxx (OP)
Hero Member
*****
Offline

Activity: 2338
Merit: 668



View Profile
August 28, 2026, 08:15:39 AM
 #1



https://x.com/ohyishi/status/2092953186193801599

OneKey founder Yishi Wang @Yishi has announced on August 27 that their internal Anzen security team had reproduced the exploit targeting Ledger Ethereum app v1.22.1 during controlled lab tests.

Although Ledger has cleared this:



https://x.com/Ledger/status/2093007184779006334

But it's good though that the hardware industry is now at a fence and reviewing everything, software, hardware, firmware and everything related for flaws that hacker can found before them and exploited it like the Coldcard incident.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS    PLAY NOW     
DubemIfedigbo001
Hero Member
*****
Offline

Activity: 1134
Merit: 722


Let love lead


View Profile WWW
August 28, 2026, 08:27:12 AM
 #2

But it's good though that the hardware industry is now at a fence and reviewing everything, software, hardware, firmware and everything related for flaws that hacker can found before them and exploited it like the Coldcard incident.
Ledger is actually taking security seriously through their internal security audits and security bounty programs, I give them credit for that, and for the vulnerability, they've fixed it in the app updates and that is a very good one.

Every system has vulnerabilities, but remaining committed to identifying and fixing those vulnerabilities early enough before a scammer exploits it is key.  Every wallet provider should be intensifying efforts with AI-driven bug identification approach, it seems AI deployment can catch these bugs faster.

Note: This topic isn't about Bitcoin, you can move it to the Hardware wallets board.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
Charles-Tim
Legendary
*
Offline

Activity: 2380
Merit: 6509


Leading Crypto Sports Betting & Casino Platform


View Profile
August 28, 2026, 09:12:37 AM
 #3

@cryptomaniac_xxx
There is an existing thread created some hours ago about this which was created on the right board that it is supposed to be created. It is better you lock this thread instead, to avoid people repetitive posts.

This is the thread:
Ledger hacked or vulnerable

The vulnerability was fixed in the in the 1.22.2 before OneKey saw the vulnerability.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
AVE5
Sr. Member
****
Offline

Activity: 1008
Merit: 368


Winning & Loosing is the option. Take a decision


View Profile
August 28, 2026, 09:34:38 AM
 #4

But it's good though that the hardware industry is now at a fence and reviewing everything, software, hardware, firmware and everything related for flaws that hacker can found before them and exploited it like the Coldcard incident.

Kudos to the external research team who were able to identify the vulnerability of the brand in advance before hacker's finds its weakness and uses the medium of the outdated ledger software to invade targets.
It was also quite a quick reaction for the team being regenerated an updated software to curb the security threat.
For those using the ledger wallet, don't forget to also update the fireware after updated the wallet with the latest version as instructed.
Perhaps the ledger brand and teams has proven how effortlessly they're awake in their lab troubleshooting to avoid flaws before user's falls victim over their ignorant.
With numerous of hardware wallets being attacked and vulnerable to be hacked always reminds us that no technological security devices or software is risk free.

m2017
Legendary
*
Offline

Activity: 2590
Merit: 1710


keep walking, Johnnie


View Profile
August 28, 2026, 04:02:38 PM
 #5


I believe that cross-testing of hardware wallets by third-party laboratories (often those of competitors) has a beneficial effect on the reliability of these devices. It is far better for bugs and vulnerabilities to be discovered by ethical hackers than by unethical ones. Furthermore, this keeps the industry on its toes, as competition for market share drives improvements in HW device security. This "battle" between manufacturers ultimately works to the benefit of device owners.

It is better for device reliability to improve this way than for the Coldcard situation to repeat itself. If in-house engineers cannot detect and fix a bug within five years... Let the competitors' engineers do it, at least.


Ledger certainly talks a good game here. But how can you update devices they’ve stopped supporting? Take Ledger Nano, for example. No way.

SamReomo
Hero Member
*****
Offline

Activity: 1638
Merit: 979


BitList.co - The directory of genuine services


View Profile
Today at 04:04:34 PM
 #6

I believe that cross-testing of hardware wallets by third-party laboratories (often those of competitors) has a beneficial effect on the reliability of these devices. It is far better for bugs and vulnerabilities to be discovered by ethical hackers than by unethical ones. Furthermore, this keeps the industry on its toes, as competition for market share drives improvements in HW device security. This "battle" between manufacturers ultimately works to the benefit of device owners.
Yes, whatever you said is true but the ethical hackers don't get paid to find those bugs, they hardly get paid if there's bug bounty program but the unethical ones often make more money by doing shady things. They find the bugs, exploit those bugs, and empty wallets of the users and such hackers make a lot from their shady practices. A good hardware wallet should have the best security possible and they should pay ethical hackers to find bugs before the unethical ones find and exploit those bugs. I think every device manufacturer should consider paying ethical hackers to find bugs in their devices at hardware level and then at software level to have maximum security for the end users.

▄▄████████████████████▄▄
████████████████████████
██████████████████████████
██████████████████████████
███▄▄▀▀▀▀▀▀▀▀▀▀▄▄██
██████████▐████▐██████
███▀██████▀▀████▀▀███████
██████████████████████
████▄▄██▄▄▄▄███▄▄▄███████
██████▀▀▀▀▀▀▀▀▀▀▀▀██████
██████████████████████████

████████████████████████
▀▀████████████████████▀▀

..1win..
█████████████████████████
█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████
█████████████████████████

..POKER..
█████████████████████████
█████████████████████████
███████████▀▀▀███████████
███████▀▀░░▄▄▄░░▀▀███████
██████▄░░░░███░░░░▄██████
█████░▀▀█▄▄░░░▄▄█▀▀░█████
█████░██░░▀▀█▀▀░░██░█████
█████░░░░░░░█░██░▄▄░█████
█████▄░░░▄▄░█░▄▄░▀▀▄█████
███████▄▄▀▀░█░▀▀▄▄██████
███████████▄█▄███████████
█████████████████████████
█████████████████████████

..GAMES..
█████████████████████████
█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
█████████████████████████
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!