OneKey successfully reproduced a transaction replacement attack on an outdated Ledger Ethereum app, proving the exploit is real, not theoretical.
This isn't a whitepaper warning or a hypothetical threat model. Researchers at OneKey physically recreated the attack in a controlled lab environment, targeting the Ledger Ethereum app before version 1.22.2. The result: a transaction could be silently swapped out during the signing process, meaning what you see on screen is not what you're actually signing.
That's the nightmare scenario every hardware wallet is supposed to prevent.
What Actually Happened
The attack falls into a category known as a "transaction replacement" or "blind signing" exploit. During the signing flow, a malicious actor with the right access could substitute the transaction details, redirecting funds to a different address than the one displayed on the device. The user confirms what looks legitimate. The chain records something else entirely.
OneKey's lab reproduction was a direct response to the vulnerability Ledger quietly patched in its Ethereum app update 1.22.2. Ledger has confirmed no user funds were lost as a result of this flaw in the wild.
But that's not the part that should comfort you.
The Part Nobody Is Talking About
The fact that a competing hardware wallet company could reproduce this exploit in-house, using publicly available information, means the attack surface was real and accessible. It wasn't buried in some obscure academic paper. OneKey's team found it, built it, and demonstrated it.
This is how the security community is supposed to work. But it also means the window between "vulnerability exists" and "bad actor exploits it" may be narrower than Ledger's patch cycle.
Ledger has had a turbulent 18 months of trust issues, from the Recover controversy to connector library hacks. Each incident chips away at the foundational promise of hardware wallets: that what you see is what you sign.
What You Should Do Right Now
If you use a Ledger device, open Ledger Live and confirm your Ethereum app is running version 1.22.2 or higher. Do not interact with any Ethereum transactions until you have verified this. The update is available now and takes under two minutes to apply.
Broader lesson: hardware wallet security is not a one-time purchase, it's an ongoing practice. Firmware updates are not optional extras. They are the difference between a secure vault and a well-designed decoy.
Watch OneKey's follow-up disclosures closely. A company that publishes reproductions like this is either building credibility fast, or shaking loose more skeletons from the hardware wallet industry's closet. Either way, Ethereum holders need to pay attention.