OneKey demonstrated how an outdated Ethereum app could sign a transaction different from the one shown on a Ledger device.

OneKey demonstrated how an outdated Ethereum app could sign a transaction different from the one shown on a Ledger device.

OneKey said it executed a “transaction replacement attack” against an older version of Ledger, but the wallet provider had already fixed the vulnerability in a previous upgrade.