TLDR OneKey’s security team recreated a transaction substitution flaw against an outdated version of Ledger’s Ethereum app. Ledger says it patched the issue with app version 1.22.2 before OneKey went public with its findings. The bug let a compromised host swap transaction detail...