TechNewsReel
Live

Ledger Patches Ethereum App Race Condition That Could Overwrite Transactions

A vulnerability in version 1.22.1 allowed for a transaction-replacement attack, threatening the core 'what you see is what you sign' security principle.

TechNewsReel Newsroom · August 27, 2026

A race condition in Ledger's Ethereum app could have allowed attackers to replace a legitimate transaction with a malicious one after a user reviewed it but before it was signed. The vulnerability, which affected version 1.22.1 of the app, highlights a critical failure point in the independent verification process of hardware wallets.

The flaw was demonstrated by OneKey's Anzen security team, who showed that a race condition existed between the transaction display logic and the underlying transaction buffer. This allowed an attacker to overwrite the transaction waiting to be signed while the user was still reviewing a legitimate one. Ledger responded by stating the vulnerability was identified internally and patched in version 1.22.2 on August 13, prior to OneKey's public demonstration. The company maintains there is no evidence the exploit was ever used in the wild.

The Patch Cycle

Following the initial fix on August 13, Ledger implemented a further correction for the underlying issue in Secure SDK version 26.6.1 on August 21. To ensure full protection, Ledger now recommends that all users install Ethereum app version 1.22.3 or later. This latest version addresses both the race condition and a separate, unrelated transaction-display vulnerability.

Ledger's Donjon security research team emphasized that "all software has bugs," noting that updateability is a core component of the company's security architecture. This stance was echoed by Ledger CTO Charles Guillemet, who characterized the demonstration against an outdated version as a "lab exercise" rather than a new finding, given that the fix had already shipped.

Industry Implications

This incident underscores a threat to the "what you see is what you sign" (WYSIWYS) principle, which is the primary security value of a hardware wallet. When a race condition can decouple the displayed transaction from the one actually signed, the device's role as an independent verifier is compromised. This necessitates more rigorous and frequent update cycles for users to maintain the integrity of their funds.

Broader Security Context

The discovery comes during a period of intense scrutiny for hardware wallet manufacturers. The industry is currently reeling from a significant exploit involving Coldcard air-gapped wallets, which resulted in losses exceeding $130 million in Bitcoin. This environment has heightened the tension between security researchers and manufacturers over whether lab-based demonstrations on older software versions constitute actual "hacks."

Users are encouraged to verify their current app versions and update immediately to version 1.22.3 or higher to mitigate these risks.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.