Ledger's Ethereum App Could Sign Fake Transactions: Here's Why You Shouldn't Panic Yet
A security researcher just demonstrated that a Ledger hardware wallet could be tricked into signing a completely different transaction from the one displayed on screen — and most users had no idea this was ever possible.
OneKey, a competing hardware wallet company, published findings showing how an outdated version of Ledger's Ethereum app contained a vulnerability that allowed a malicious transaction to be approved without the user seeing what they were actually signing. In the world of self-custody, where 'what you see is what you sign' is the entire trust model, that is about as serious as it gets.
But here is the critical detail before you consider throwing your Ledger in a drawer: Ledger says the vulnerability was patched before OneKey even published the research. The company confirmed the fix was already live, meaning users running an updated Ethereum app on their device are not exposed.
What Actually Happened
The exploit targeted a specific weakness in an older version of Ledger's Ethereum application, not the device firmware itself. The attack required a user to have that outdated app installed and to connect their wallet to a compromised or malicious interface. It was not a remote hack. Nobody's funds were drained. No private keys were exposed.
OneKey's disclosure appears to follow responsible security research practices, timing the publication after a fix was already in place. The optics, however, are brutal for Ledger, a company still rebuilding trust after the 2020 customer data breach and the deeply controversial Ledger Recover announcement in 2023, which rattled the self-custody community.
The Bigger Problem Nobody Is Saying Out Loud
This incident is a sharp reminder that hardware wallets are not magic boxes. They are software-dependent devices, and that software has bugs. The 'verify on device' promise only holds if the app running on your device is actually showing you accurate data.
Competing wallets like Trezor, Coldcard, and OneKey itself are already using this moment to quietly position themselves as more transparent alternatives. Expect that marketing to get louder.
What Hardware Wallet Holders Should Do Right Now
First, open Ledger Live and confirm your Ethereum app is fully updated. If you have not updated in several months, do it before your next transaction, no exceptions. Second, always verify contract addresses independently before signing anything, regardless of what your device displays. Third, watch how Ledger responds publicly over the next 48 hours. How a company handles disclosure moments like this reveals more about its security culture than any marketing campaign ever could.
The patch is live. The vulnerability is closed. But the trust deficit at Ledger remains very much open.