Ledger patched a vulnerability in its Ethereum hardware wallet app on August 12, 2026, shipping version 1.22.2 without public notice. The APDU command race condition could have allowed malicious dApps to swap legitimate transactions for harmful ones during clear signing. Security researcher TestMachine publicly disclosed the issue between August 21 and August 23, 2026, prompting Ledger CTO Charles Guillemet to call the disclosure fear-mongering while claiming internal discovery.
Aug 27, 2026 · 6 sources
Aug 26, 2026 · 6 sources
Aug 26, 2026 · 6 sources
Aug 24, 2026 · 2 sources
Story comments
Loading comments…