BTC $79,129.74 -0.80%
ETH $2,488.58 +0.09%
BNB $744.36 -0.46%
XRP $1.40 -0.84%
SOL $104.40 -1.44%
TRX $0.3352 +0.06%
DOGE $0.0902 +1.26%
ADA $0.2208 +1.20%
BCH $259.77 +1.08%
LINK $13.02 +5.94%
HYPE $87.05 -1.66%
AAVE $132.79 -0.87%
SUI $0.8242 +3.13%
XLM $0.1920 +3.86%
ZEC $1,174.97 +0.43%
BTC $79,129.74 -0.80%
ETH $2,488.58 +0.09%
BNB $744.36 -0.46%
XRP $1.40 -0.84%
SOL $104.40 -1.44%
TRX $0.3352 +0.06%
DOGE $0.0902 +1.26%
ADA $0.2208 +1.20%
BCH $259.77 +1.08%
LINK $13.02 +5.94%
HYPE $87.05 -1.66%
AAVE $132.79 -0.87%
SUI $0.8242 +3.13%
XLM $0.1920 +3.86%
ZEC $1,174.97 +0.43%

onekey

All
Article
Flash

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

OneKey founder Yishi spoke out about the Resupply attack incident, calling on projects like Curve to refund user losses

ChainCatcher news, OneKey founder Yishi publicly stated about "Curve ecosystem DeFi protocol Resupply suffering a price manipulation attack resulting in a loss of $9.6 million," demanding that Curve provide a fair solution for every investor and return the user funds lost due to serious technical errors by the project team.Yishi revealed that he is one of the three major investors in Resupply, and the losses from this incident amount to millions of dollars. He accused the team of banning reasonable questioners on Discord and lacking the necessary accountability. He emphasized that the vulnerability stemmed from the failure to destroy the initial shares when deploying the ERC4626 vault, allowing attackers to mint shares at almost zero cost and drain the vault, which constitutes a protocol-level design and deployment error.Yishi stated that it is unreasonable for the Resupply team to shift the losses onto the insurance pool depositors, as the insurance pool is meant for black swan events and market fluctuations, not to cover the team's technical negligence. He also pointed out that Curve, Convex, and Yearn had participated in supporting Resupply in various forms and had gained actual benefits from it, and should not shirk responsibility afterward. He called for the relevant parties to bear the necessary costs and return user assets.In response to the incident, Curve stated this morning, "Although Resupply was not developed by the Curve team, its creators are experienced, and we believe they will do their best to address the issue. The insurance pool is intended to provide protection for such security incidents, and any recovered assets should be prioritized for processing."
app_icon
ChainCatcher Building the Web3 world with innovations.