Decrypt · 8/27/2026

Ledger patches Ethereum app flaw after OneKey exploit demo

Ledger patches Ethereum app flaw after OneKey exploit demo

Ledger isn't hacked, but it did have a close call. Security researchers at OneKey recently demonstrated a vulnerability where an outdated Ethereum app could trick a hardware wallet into signing a malicious transaction while displaying a legitimate one. It's the kind of blind-signing nightmare that keeps self-custody users awake at night. Ledger officials confirmed the flaw existed but claim they neutralized the threat with a patch before the findings went public. The company insists no user funds were drained during the disclosure process. To stay safe, users just need to open Ledger Live and trigger a manual update for their device apps. This incident serves as a blunt reminder that even cold storage requires constant software maintenance. Have you checked your firmware version lately?

Read full story at Decrypt
Share:XLinkedInFacebook