- Ledger’s Ethereum app version 1.22.2, released August 12, patched a bug in how the app handled transaction review, according to the project’s own public changelog.
- The bug could have let a malicious application swap the transaction a user was approving for a different one while the device screen still showed the original, according to TestMachine, the firm that found it.
- Ledger has not published a public security bulletin for the fix, and a similar fix for the same type of flaw remains open, unmerged, in the shared code library behind all of Ledger’s apps.
On August 12, Ledger shipped an update to its Ethereum hardware wallet app that patched a bug in the screen used to review a transaction before signing it.
TestMachine, an AI-driven smart contract security firm, says its automated scanning tool, Azimuth, found the flaw: a malicious application with the right browser permissions to talk to the device could send a second command while a transaction was still on screen for approval, swapping in a different one without the display changing.
Found by Azimuth during an autonomous scan of the Ledger Ethereum app. Validated on Flex. Shared and verified with the team. Declining any bounty. Same shared APDU/UI code across Nano X, Nano S Plus, Stax, Apex.
The power of always on securityhttps://t.co/fH5mO97Kkp
— TestMachine (@testmachine_ai) August 22, 2026
TestMachine says it validated the bug on a Ledger Flex device, reported it to Ledger, and declined the bounty Ledger offered.
There’s some FUD circulating about Ledger signers, pushed by a “smart contract security” company claiming a vulnerability in the Ledger Ethereum app.
There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability…
— Charles Guillemet (@P3b7_) August 23, 2026
Ledger’s chief technology officer, Charles Guillemet, disputes that account. In a post on X, he said Ledger’s own security team, Donjon, found and fixed the same bug independently, using an in-house AI tool called Cerberus, and that TestMachine only contacted Ledger’s bounty program after the patch had already shipped.
“That’s not security research. That’s manufacturing fear for attention.”
Guillemet’s central point checks out. The changelog entry confirming the fix predates TestMachine’s public thread by roughly two weeks, and Ledger’s own April announcement of Cerberus, described by the company as an AI security harness built to find and patch vulnerabilities at machine speed, supports his account that Donjon already had AI-assisted tooling running before this bug surfaced. The devices sharing the affected code include the Nano X, Nano S Plus, Stax, Apex and Flex.
What Guillemet’s account leaves out
Ledger keeps a public archive of its own security bulletins, going back to 2018, built for exactly this kind of disclosure. As of this week, no bulletin has been added for this bug.
The most recent Ethereum-related entry in that archive is from November 2023 and concerns an unrelated issue in Ledger Live. The app’s own changelog gives no more detail than the words “security issues.”
A second, related fix has not shipped at all. In June, a Ledger engineer opened a change to the code library shared across every Ledger app, adding a lock that rejects a second incoming command while a user is still reviewing a transaction, the same mechanism TestMachine says was missing here.
It is not confirmed to be the exact fix used in the Ethereum app patch, but it targets the identical weakness, and merging it would close the same gap across Ledger’s other apps, not just Ethereum. Closing this out fully requires three things: the app patch, a public bulletin, and that shared fix landing. Only the first has happened.
A security vendor with its own stake in the story
TestMachine is not a disinterested party either. The firm has raised more than 6.5 million dollars in venture funding to build Azimuth and its other AI auditing tools, and a public finding against a wallet maker as large as Ledger is also a marketing moment for a young security vendor competing for attention in a crowded field.
Neither side’s incentive changes the practical guidance for anyone using an affected device. Guillemet’s own recommendation, and the one that actually addresses this bug, comes down to three things:
- Update the Ledger Ethereum app itself, which carries the fix as of version 1.22.2.
- Update the device’s firmware as well, since Ledger ships some security work at that layer.
- Keep other software involved in approving transactions current too, since that is how new fixes reach users automatically, according to Guillemet.
Shared-code fix will land, and whether Ledger plans to say anything about it in public before it does. Separately, a Ledger user claimed about 2.3 million ADA ($333,000) was drained without signing a transaction. The cause remains unconfirmed and has not been publicly linked to the Ethereum app bug.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.
















