OneKey said it executed a “transaction replacement attack” against an older version of Ledger, but the wallet provider had already fixed the vulnerability in a previous upgrade.