Ledger and OneKey Clash Over Ethereum App Flaw Credit
OneKey's Anzen security team demonstrated a vulnerability in Ledger's Ethereum app that could allow signing transactions different from what is displayed. Ledger claims the flaw was already patched before OneKey's public announcement, sparking a dispute over discovery credit and responsible...
Ledger and OneKey Clash Over Ethereum App Flaw Credit
OneKey's Anzen security team this week demonstrated a vulnerability in Ledger's Ethereum app that could allow a device to sign a transaction differing from what is displayed on-screen. Ledger immediately pushed back, claiming the flaw had already been patched before OneKey's public announcement.
The vulnerability, often called a "blind signing" or display-mismatch exploit, is particularly dangerous because users rely on the hardware wallet's screen as the final verification layer before approving a transaction. If what is shown and what is signed diverge, the security model of the device collapses entirely.
Ledger frames the disclosure as a reproduction of its own internal security work rather than an independent discovery. The company is not disputing that the flaw existed, only that it no longer does.
"OneKey demonstrated how an outdated Ethereum app could sign a transaction different from the one shown on a Ledger device, but the wallet maker says the vulnerability had already been fixed."
Ledger, via company statement
The semantics matter. OneKey's Anzen team characterized their work as "hacking" Ledger's Ethereum app, language implying an active, unpatched threat. Ledger's counter-framing, that OneKey "just copied its findings," is equally pointed. Both characterizations do reputational work, and neither is a neutral technical description.
Legitimate concerns exist on both sides. If Ledger's patch was recent, a meaningful share of users running older versions of the Ethereum app remain exposed right now. The "already patched" claim only protects users who have updated. Ledger has not publicly disclosed what percentage of active devices are running the fixed version. Hardware wallet update adoption is notoriously uneven. Unlike a mobile app or browser extension, users must manually connect their device and step through firmware or app updates. Many do not. The window between a patch being available and universal deployment can span weeks or months, and during that window, the vulnerability is functionally live for a large subset of users.
The broader issue this dispute surfaces is the absence of standardized responsible disclosure norms in the hardware wallet industry. In traditional software security, coordinated disclosure typically involves the researcher notifying the vendor privately, agreeing on a remediation timeline, and releasing findings publicly only after a patch is available. When that process breaks down, disputes over timing, credit, and severity become inevitable. Whether OneKey followed that process, or whether Ledger's internal timeline genuinely predated any contact from OneKey, is the factual core of the disagreement. Neither company has published a detailed timeline to settle it.
Ledger's reputation has taken security-related hits before. A 2020 data breach exposed the personal information of roughly 270,000 customers. A late-2023 supply-chain attack on the Ledger Connect Kit library briefly compromised multiple DeFi front ends before Ledger patched it within hours. Each incident reinforced that hardware wallet security extends well beyond the device itself. This latest dispute differs in character, centering on the app layer and disclosure process rather than a live exploit, but it arrives in a market where user trust is already calibrated carefully.
For ETH holders, the immediate action is straightforward: open Ledger Live and verify the Ethereum app is running the latest version. Ledger has not published a CVE (Common Vulnerabilities and Exposures) identifier for this flaw, which makes independent verification of the patch difficult. Publishing one would give security researchers and users a concrete reference point and would go some distance toward resolving the credibility gap this dispute has opened.
Until Ledger releases a detailed disclosure, including the patch version number, the date it was deployed, and a clear account of when OneKey first made contact, the "already patched" defense remains incomplete. A vulnerability that is fixed but not communicated is only half a resolution.






