Ledger rejected the hacking statement. OneKey re-emerged
Ledger rejected the statement that he had been attacked by hackers after the OneKey security team re-emerged its Etherwood application. On 27 August, Wang Yi, founder of OneKey, stated that the researchers had completed the attack on the Etheraf application 1.22.1 at the laboratory. Ledger identified a potential loophole, but indicated that the affected applications had been repaired prior to the OneKey presentation. This loophole, which involves communications between the Ledger device and its connection to the host, may result in new instructions covering stored signature parameters when viewing previous operations. Ledger classifies this issue as a condition of competition between time check and time of use. The defect does not disclose a assistive word or extract a private key, but may result in a protected key signing with parameters different from the information that the user sees. Ledger suggested that users update to version 12.2.3 or higher of the Taifung application to obtain broader protection。
