The founder of hardware cryptocurrency wallet manufacturer OneKey, Ishi Wan, recently disclosed on his X profile that his team successfully bypassed the security of the Ledger wallet during laboratory tests.
According to him, the vulnerability arose from a timing issue between the display of the transaction on the screen and its preparation for signing with the wallet's key. During this interval, an attacker was able to substitute the legitimate transaction with a fraudulent one.
The team conducted their tests on the Ethereum app version 1.22.1, and it is worth noting that this vulnerability has already been addressed in the latest version of the application.