跳到主内容
精选70Protos(RSS)加密货币多源精选 ×7

OneKey称攻破Ledger以太坊应用,Ledger反驳称无用户受影响

OneKey ‘hacked’ already-patched Ledger app

原文

Crypto wallet maker OneKey and cybersecurity firm Anzen claim to have hacked version 1.22.1 of Ledger’s Ethereum app. Ledger outright disagrees, saying, “No Ledger user was hacked.”

Earlier today, OneKey founder Yishi Wang detailed how his security team reproduced a transaction replacement attack that takes place while a user is reviewing a legitimate transaction.

Wang declared, “We hacked ledger,” and warned users on Ledger’s older Ethereum app to update it, noting that Ledger has already fixed this in version 1.22.3.

Ledger says OneKey didn’t actually hack anything

Ledger’s Chief Technology Officer Charles Guillemet responded hours later, claiming that “reproducing an already-patched bug is not ‘hacking Ledger.’”

He added, “No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding.”

A Ledger spokesperson told Protos that OneKey “took the already disclosed findings and tried to replicate them in a lab environment.”

Ledger confirms customer data leaked in third-party Global-e breach

Read more: KuCoin criticized for helping ‘launder’ $9.5M from fake Ledger app

The Ledger Donjon team claimed this fix was shipped on August 13 in version 1.22.2, further contradicting OneKey’s claims.

Protos has reached out to OneKey for comment and will update this piece should we hear anything back.

Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

The post OneKey ‘hacked’ already-patched Ledger app appeared first on Protos.

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

关联讨论

同一事件的更多信源

相似阅读

另一事件,读法相近