BlockBeats News, August 28, the OneKey security team, OneKey Anzen, recently replicated the Ledger vulnerability disclosed by TestMachine and found that the Ledger Ethereum application version 1.22.1 has a transaction replacement vulnerability. The user under attack may see Transaction A on their hardware screen that they are reviewing, but the device may sign off on Transaction B that the user has never seen.
OneKey Anzen stated that the root cause of this issue is a race condition between the transaction display logic and the underlying buffer; the premise of the attack is that the host side has been compromised by a malicious dApp or intermediary software.
On August 22, TestMachine pointed out a security vulnerability in the well-known crypto wallet Ledger. Ledger's CTO responded the next day, stating that the vulnerability had been fixed in an update released about two weeks ago, and users just need to update the application, advising the community "not to panic." However, public information shows that the formal tag for version 1.22.2 on Ledger's GitHub did not appear until August 24.
As of the time of writing, Ledger has updated the latest developments on its official website. They stated that they have fixed the issue through application-level validation and SDK layer and released Ledger Secure SDK v26.6.1 on August 21, with the relevant applications rebuilt and released. Users need to update the application through Ledger Live; updating only the device firmware is not sufficient to complete the fix. However, Ledger stated that there is currently no evidence that the vulnerability has been exploited.

