OneKey reproduces transaction replacement attack on outdated Ledger Ethereum app

الملخص:OneKey said it executed a “transaction replacement attack” against an older version of Ledger, but the wallet provider had already fixed the vulnerability in a previous upgrade.

The in-house security team at open-source wallet provider OneKey said it successfully reproduced an exploit targeting an outdated version of Ledgers on-device Ethereum application in a test environment.

OneKey founder and CEO Yishi Wang said they executed a “transaction replacement attack” against Ledger Ethereum app 1.22.1 by exploiting a previously patched vulnerability that lets attackers overwrite the transaction waiting to be signed while the user is still reviewing the legitimate transaction.

Ledger said exploiting the vulnerability required control over communications between the device and its host, such as through malware, compromised wallet software or a hostile webpage. Ledger added app-level safeguards with Ethereum app 1.22.2 released on Aug. 13, before fixing the underlying issue in Secure SDK 26.6.1 on Aug. 21.

“No Ledger user was hacked. Whats described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app,” Ledger wrote in a Thursday X post.

The security test follows the Coldcard exploit in July, when attackers exploited a firmware bug introduced in March 2021 that weakened seed randomness on some Coldcard wallets, leaving the resulting private keys vulnerable to brute-force attacks.

Ledger had previously said its devices were not affected by the Coldcard vulnerability because recovery phrases are generated using a certified source of randomness built into the devices security chip.

The vulnerability reproduced by OneKey is unrelated to seed generation and instead affects how transactions are handled during the signing process.

Magazine: Inside the ‘fake police raid’ that forced a $1M Bitcoin transfer

عدم اعطاء رأي

الآراء الواردة في هذه المقالة تمثل فقط الآراء الشخصية للمؤلف ولا تشكل نصيحة استثمارية لهذه المنصة. لا تضمن هذه المنصة دقة معلومات المقالة واكتمالها وتوقيتها ، كما أنها ليست مسؤولة عن أي خسارة ناتجة عن استخدام معلومات المقالة أو الاعتماد عليها.
المنشور السابق

تقدّر Chainalysis حجم نشاط العملات المشفرة الخاضع للضريبة بـ457 مليار دولار وتقول إن CARF يفوّت معظمه

التالي

ارتفاع عملة ENA بنسبة 10% بعد طرح Ethena لإعادة شراء الرموز الممولة بالإيرادات للتصويت