My timeline spent all of yesterday screaming that Ledger got hacked. Screenshots of a tweet from a rival wallet CEO, panicked replies asking whether to move funds, the usual chorus of “hardware wallets are dead.” After the Coldcard summer, people are jumpy, and I get it.
So I did what I always do before touching my own device: read the actual disclosure, read the actual claim, and compared the two. Here’s the short version. A competitor reproduced a real bug in a lab, two weeks after Ledger patched it, and nobody lost any money. The long version is worth your five minutes, because there’s one thing you should still do today.
What OneKey Actually Claimed
On August 27, OneKey founder Yishi Wang posted that his company’s Anzen security team had “hacked Ledger.” The team rebuilt version 1.22.1 of Ledger’s Ethereum app and pulled off a transaction replacement attack against it end to end in their lab.
Two details matter here. First, OneKey makes hardware wallets that compete directly with Ledger. Second, version 1.22.1 was already outdated when the demo went public. Ledger shipped 1.22.2 on August 13 with a fix for this exact issue, and the current recommended version is 1.22.3 or later.
None of that makes the research fake. The bug existed, and reproducing it takes real skill. The framing, though, is the part doing the damage on your timeline.
Related: What is Tornado Cash, and how do Crypto Mixers work.
What the Bug Does
Ledger’s own disclosure describes a race condition between the transaction display logic and the underlying transaction buffer. In plain English: the device shows you one set of transaction details, you press approve, and a compromised host swaps the data before the device signs. You’d confirm sending 0.5 ETH to your own address while the device actually signs 50 ETH to the attacker.
That’s a nasty class of bug. The entire point of a hardware wallet screen is that what you see is what gets signed. Ledger says the weakness crept in through the Secure SDK back in August 2025 and affected every SDK version through 26.6.0, so it sat in shipped code for about a year before the fix landed in 26.6.1.
Now the limits, because they matter just as much. The attack required an adversary already sitting between your device and your computer, through malware, a compromised wallet app, or a malicious webpage. The device had to be plugged in and actively signing. You had to approve a transaction while the attack ran in the background. Seed phrases and private keys inside the Secure Element were never exposed. The bug changed what got signed, not who held the keys.
Why Ledger Says This Isn’t a Hack
Ledger’s CTO Charles Guillemet pushed back hard, calling the demo a lab exercise rather than a finding. His argument: reproducing a bug that was patched weeks earlier doesn’t equal hacking the company or its users.
I find that mostly fair, with one caveat. Ledger reports no evidence anyone exploited the flaw in the wild, and no stolen funds have been publicly linked to it anywhere. A year is a long window, though, and “no evidence” is not the same as “impossible.” If someone did quietly exploit this, we’d expect to see drained wallets and on-chain forensics by now. We haven’t. That’s reassuring, not conclusive.
What I’d push back on is the idea that competitors poking holes in each other is a scandal. It’s the system working. Last year Ledger’s research team found a firmware integrity bypass on Trezor’s Safe 3 and Safe 5 and reported it, which I covered in my Trezor safety breakdown. Now OneKey has returned the favor. The only difference is that Ledger disclosed quietly while OneKey chose the “we hacked Ledger” headline. Marketing, not malice, but marketing nonetheless.
Who Should Actually Worry
Honestly, the group at risk is small but real: Ledger users who haven’t updated their Ethereum app since mid-August and who also have malware or a compromised wallet extension on their machine. If that second condition applies to you, an outdated Ledger app is not your biggest problem.
For everyone else, this is a patch-and-move-on situation. My own device, the same one I wrote about when everyone asked whether Ledger was safe after Coldcard, got its Ethereum app updated this morning and went back in the drawer.
How to Check Your Ethereum App
Open Ledger Live and go to My Ledger. Install any pending app updates, then confirm the Ethereum app version shown on the device itself reads 1.22.3 or higher. One trap worth flagging: updating firmware alone doesn’t replace apps built with the affected SDK. The Ethereum app needs its own update. Developers building third-party Ledger apps have their own homework, since anything compiled with an older SDK needs a rebuild on 26.6.1 or later.
While you’re in there, verify every transaction on the device screen before approving, every single time. This bug was designed to beat that habit, but the habit still stops the vast majority of drainers that don’t have a firmware bug to lean on.
Keep This Content Free
Sorting real security news from competitor marketing takes time, and nobody paid me for this one. Ledger dropped our affiliate account a while back and OneKey has never emailed us. If you want to support the site, sign up on OKX or Bybit through our referral links. It costs you nothing and keeps the lights on.
Final Words
Was Ledger hacked? No. A competitor reproduced a patched bug in a lab and wrote a headline that would get traction, and it did. The bug was real, it lived in shipped code for about a year, and Ledger fixed it before the claim went public. No user funds appear to have moved because of it.
The lesson I keep coming back to after this summer is that “hardware wallet” was never a synonym for “done thinking about security.” Coldcard shipped broken randomness for five years. Trezor’s shipping partner leaked customer addresses. Ledger let a signing bug sit in its SDK for twelve months. Every brand takes a hit eventually, and the users who come through fine are the ones who update on time, verify on the device screen, and refuse to panic-move funds because a screenshot told them to.
Update the app. Ignore the timeline.
As always, don’t forget to claim your bonus on Bybit below. See you next time!
FAQ
Did Ledger get hacked in August 2026? No. OneKey’s security team reproduced a transaction replacement bug against an outdated version of Ledger’s Ethereum app in a lab. Ledger had already patched the flaw on August 13, and no funds have been linked to it.
Could this bug steal my seed phrase? No. The flaw only affected which transaction data the device signed. Private keys and recovery phrases inside the Secure Element stayed isolated throughout.
Which Ledger Ethereum app version is safe? Ledger recommends 1.22.3 or later. Check the version on the device screen itself through Ledger Live’s My Ledger tab, not just in the desktop app.
Does a firmware update fix this? Not on its own. The bug lived in the Ethereum app, so the app needs updating separately. Firmware and apps are different components on a Ledger device.
Is OneKey trustworthy given they’re a competitor? Their research appears technically sound, and competitors auditing each other is normal in this industry. Treat the findings as legitimate and the “we hacked Ledger” framing as marketing.
Credit: Source link


















