OneKey Reproduces Transaction Replacement Vulnerability in Legacy Ledger Ethereum App in the Lab
According to Cointelegraph, open-source wallet provider OneKey stated that its security team successfully reproduced a "transaction replacement attack" targeting the legacy Ledger Ethereum app version 1.22.1 in a laboratory environment. This vulnerability could allow attackers to replace transactions awaiting signature while users review legitimate ones, though successful exploitation requires controlling communication between the device and the host, such as through malware, compromised wallet software, or malicious websites.