OneKey Anzen retweeted
we hacked ledger. the @OneKey_Anzen team has successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1 in our lab. the bug is a race condition between the transaction display logic and the underlying transaction buffer. an attacker can overwrite the transaction waiting to be signed while the user is still reviewing a legitimate one. in simple terms: - you see transaction a on your ledger. - you approve transaction a. - your ledger can end up signing transaction b. - and you never see transaction b. to reproduce this, we built the 1.22.1 ELF ourselves, fixed the speculos reset 502 issue, and got the full attack flow working end to end. ledger fixed this in ethereum app 1.22.3. if you’re still on an older version, update it.
Community note
The described bug matches a vulnerability publicly disclosed by TestMachine on August 22 which Ledger fixed in Ethereum app 1.22.2, not 1.22.3. donjon.ledger.com/lsb/023/ github.com/LedgerHQ/app-e… x.com/testmachine_ai…
187
165
1,221
1,453,114
STAY SAFE.
OneKey users are not affected by the recent COLDCARD/Coinkite RNG issue. The issue is specific to COLDCARD’s random number generation implementation, firmware, and related dependencies. OneKey does not use that code, implementation, or dependency stack. When a wallet is created on a OneKey hardware device, the entropy used to generate the recovery phrase is produced entirely on-device. Independent random sources from both the secure element and the MCU are combined, so the process does not rely on a single component. Unlike COLDCARD’s non-EAL-certified architecture, OneKey’s core secure element has passed a rigorous EAL6+ security evaluation, which includes strict requirements for secure random number generation. OneKey firmware is also fully open source and continuously reviewed by the security community. Protecting user assets has always been our highest priority. We continue to invest heavily in security research, testing, and real-world attack defense to help build a safer future for self-custody. 🫡 Stay safe.
1
3
1,441
we’ve just launched the official website for @OneKey_Anzen. anzen lab is onekey’s in-house security team. we secure our hardware, firmware, and apps before they ship, coordinate responsible disclosure with external researchers, and open source the tools and research behind our work. found a real vulnerability? report it to us. if it’s valid, we’ll pay a bounty and give you full credit.
2
8,654
OneKey Anzen team is heading to Black Hat USA @BlackHatEvents conference 2026. We’ll be sharing our latest research on stage this August. Talk details coming soon, see you in Vegas.
1
6
5,957
⚠️ Axios supply chain attack notice: Axios is one of the most popular HTTP client libraries for JavaScript/Node.js. AI tools like Cursor, Copilot, and Claude often generate npm i axios without pinning a version, which can install the malicious 1.14.1 or 0.30.4. Quick actions: > Check package.json and your lockfile > Safe versions: 1.14.0 (1.x) / 0.30.3 (0.x) > If affected, treat the machine as compromised and rotate all keys/credentials immediately OneKey security team has reviewed all our repos — we are not impacted. We use strict version pinning across projects. Supply chain attacks are rising. Pin your dependencies.
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
3
9
2,922
OneKey Anzen is the Security Lab at @OneKeyHQ. Follow us to get the the latest news from our research👊😎
4
4
17