OneKey’s demonstration was a controlled lab reproduction against Ledger Ethereum app 1.22.1, not evidence of a live Ledger compromise. Ledger’s Ethereum app 1.22.3 addressed two further signing and display flaws—LSB 024 and LSB 025.
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened with Ledger’s Ethereum app security vulnerabilities involving OneKey’s controlled reproduction of the already-patched LSB-023. Article summary: OneKey’s result was a controlled lab reproduction against the outdated Ledger Ethereum app 1.22.1, not evidence of a live compromise. Ledger said LSB-023 had already been identified internally and patched in 1.22.2, and . Topic tags: general, documentation, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks,
OneKey reproduced a genuine transaction-replacement vulnerability in Ledger’s older Ethereum app 1.22.1, but the test was conducted in a controlled lab environment. Ledger says the flaw had already been fixed in version 1.22.2 before the demonstration became public and that it found no evidence of attacks against users. 31731
The episode nevertheless exposed a broader issue: a hardware wallet’s security depends not only on its private-key isolation, but also on whether the device faithfully displays the transaction it ultimately signs.
The vulnerability, tracked by Ledger as LSB-023, involved command interleaving during an on-device transaction review. A host could submit a new APDU command while an earlier command was still awaiting the user’s response. Because signing parameters remained in shared state during that review, those parameters could potentially be changed after they appeared on the device but before the signature was produced. 3
In practical terms, the display could show transaction A while the device signed transaction B. OneKey’s Anzen team reproduced that behavior using the outdated 1.22.1 Ethereum app in a lab. That demonstrates exploitability of the old software; it does not demonstrate that Ledger’s production systems or users were compromised. 172332
Ledger says it had identified the vulnerability through its own security process and released safeguards in Ethereum app 1.22.2. Reporting also says the underlying issue was addressed in Secure SDK 26.6.1. 172124
Ledger’s statement was categorical: “No Ledger user was hacked.” The available reporting describes no known losses connected to OneKey’s reproduction, but that statement should be understood as a report about observed exploitation—not proof that exploitation would have been impossible on an affected version. 172031
The distinction matters. A lab reproduction can confirm that a vulnerable code path works under the required conditions without showing that criminals used it in the wild.
Version 1.22.3 addressed two other Ethereum-app vulnerabilities that remained relevant after the 1.22.2 update. Ledger’s security bulletin index names them as LSB-024 and LSB-025. 46
LSB-024 concerned an integer or operation-count handling flaw in clear signing. A specially formed batch containing 257 operations could cause the device to display only the final operation while signing the entire batch.
That is a transaction-review integrity failure. The device may still require the user’s confirmation, but the information presented for review would not faithfully describe the complete payload being signed. Ledger lists the issue as “Clear-signing bypass via array-count truncation.” 46
LSB-025 affected a swap flow. A compromised swap provider could substitute a token approval for the expected payment without triggering another device prompt. Ledger describes it as “Swap flow accepted a token approval in place of a payment.” 46
The reported limits are important. This was not described as a mechanism for creating an unlimited allowance or approving an arbitrary attacker-selected address. It could nevertheless cause a user to sign an approval they did not intend to authorize, which is materially different from the expected payment in a swap. 46
The public material supplied for this report indicates that the relevant changes for the two later flaws had reportedly been merged months before version 1.22.2 shipped, yet the fixes appeared in 1.22.3 instead. Reporting describes the omission as an unresolved release or integration question. 37
There is not enough authoritative public documentation here to establish whether the cause was release prioritization, integration failure, testing, or another internal decision. The defensible conclusion is narrower: the fixes were not included in 1.22.2, and the precise reason remains publicly unexplained. Stronger claims would go beyond the available evidence.
Ledger’s response emphasized that an updateable wallet architecture allows vulnerabilities in device applications and supporting software to be corrected and distributed. In that model, the security process is intended to identify a flaw, develop a fix, release it, and disclose the issue with technical details afterward. LSB-023 was presented as an example of that process: the flaw was identified internally, patched, and later documented in a security bulletin. 3
That argument has a clear benefit: a discovered software vulnerability does not necessarily remain permanent. But it also creates an operational requirement for users. A patch only protects a device after the affected application has actually been updated, and a delayed or incomplete release can leave related issues unresolved—as the gap between 1.22.2 and 1.22.3 illustrates. 37
The immediate takeaway is straightforward: OneKey demonstrated a real flaw in an outdated Ledger Ethereum app, but the available evidence does not show a live Ledger hack. Users should still treat the incident seriously, because LSB-024 and LSB-025 show that updating to the first available fix was not necessarily the end of the security story.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
OneKey’s demonstration was a controlled lab reproduction against Ledger Ethereum app 1.22.1, not evidence of a live Ledger compromise.
OneKey’s demonstration was a controlled lab reproduction against Ledger Ethereum app 1.22.1, not evidence of a live Ledger compromise. Ledger’s Ethereum app 1.22.3 addressed two further signing and display flaws—LSB 024 and LSB 025.