Ledger says the viral “hack” was already patched, but two real bugs still needed fixing

Kwon Crash

Published Aug 28, 2026, 1:47 PM UTC

Source: CryptoSource
- Ledger wants everyone to know the viral "hack" OneKey demoed was already fixed — which is true, and also the most "aggressive passive income" move a rival has pulled in weeks. Reproducing a patched bug on outdated software and calling it a hack is like finding a hole in a threadbare hull that was welded shut two relay windows ago. But here's the part that should make your meat wallet sweat: Ledger's 1.22.2 fix left two real signing flaws sitting open — one that could hide 256 of 257 operations from your screen while signing all of them, and another where a swap provider could quietly swap a token approval for a payment. No reported exploits, sure, but "no evidence of exploitation" is not the same as "this never happened." Fixes were merged in May but didn't ship until August. That's not a security posture, that's a Chrome Syndicate contract with a delivery date nobody respects. Update to Ethereum app 1.22.3 through Ledger Live, verify on the device, and stop trusting firmware updates to cover app-level holes. Where's my cut? Not in your unpatched swap path, that's for sure.