Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Ledger patches Ethereum app vulnerability after AI firm disclosure
00

Ledger patches Ethereum app vulnerability after AI firm disclosure

Aug 23, 2026

Ledger patched a vulnerability in its Ethereum hardware wallet app on August 12, 2026, shipping version 1.22.2 without public notice. The APDU command race condition could have allowed malicious dApps to swap legitimate transactions for harmful ones during clear signing. Security researcher TestMachine publicly disclosed the issue between August 21 and August 23, 2026, prompting Ledger CTO Charles Guillemet to call the disclosure fear-mongering while claiming internal discovery.

APDU race condition vulnerability

  • ▪No reports of funds lost to the Ledger Ethereum app vulnerability have surfaced.
  • ▪Ledger patched a vulnerability in its Ethereum hardware wallet app on August 12, 2026.
  • ▪The Ledger Ethereum app vulnerability fix shipped in Ethereum app version 1.22.2.
  • ▪The Ledger Ethereum app vulnerability attack would have required a compromised or malicious dApp to exploit the timing window.
  • ▪The Ledger Ethereum hardware wallet app vulnerability involved an APDU command race condition that could allow a malicious decentralized application to swap out a legitimate transaction for a harmful one mid-signing.
  • ▪The Ledger Ethereum app race condition could have allowed a user to think they were approving a small token transfer while actually authorizing unlimited token approvals to an attacker-controlled address.
  • ▪During Ledger clear signing flows, the race condition could have allowed a second, malicious APDU command to slip in and replace the original transaction data.

Ledger Donjon discovery

  • ▪Ledger Donjon deployed the patch for the Ethereum app vulnerability proactively before any external notice was filed.
  • ▪Ledger's internal security team Donjon discovered the Ethereum app vulnerability before any external researcher flagged it.
  • ▪Ledger Donjon used AI-assisted tools to identify and resolve the Ethereum app vulnerability.

TestMachine public disclosure

  • ▪A security researcher operating under the name TestMachine publicly disclosed the Ledger Ethereum app vulnerability between August 21 and August 23, 2026.
  • ▪Ledger CTO Charles Guillemet characterized TestMachine's public disclosure as fear-mongering.
  • ▪The Ledger Ethereum app patch landed on August 12, 2026 without a security advisory, blog post, or tweet thread.
  • ▪TestMachine detailed the potential for transaction substitution and the mechanics of the race condition in the Ledger Ethereum app.
  • ▪Ledger said almost nothing publicly about the Ethereum app vulnerability patch until a security researcher forced the conversation.
  • ▪TestMachine declined a bounty offer from Ledger.

Clear signing security

  • ▪Ledger has invested heavily in making clear signing the default, including previous work with the ERC-7730 standard aimed at standardizing how transaction data is displayed on hardware wallets.
  • ▪The Ledger Ethereum app vulnerability affected Ledger's clear signing flows, the feature designed to protect users from blind signing risks.

Perspective of TestMachine (security researcher)

  • ▪TestMachine publicly disclosed the Ledger Ethereum app vulnerability between August 21 and August 23, 2026, forcing Ledger to acknowledge the issue after the company had remained silent for over a week following the August 12 patch.
  • ▪TestMachine declined a bounty offer from Ledger after publicly disclosing the Ethereum app vulnerability.

2 sources

BeInCrypto
AI Firm Exposes Ledger Bug, CTO Calls It Fear-Mongering After Quiet Fix
View source article
Crypto Briefing
Ledger fixes vulnerability in Ethereum app's signing flows
View source article

Featured stories

View more in Decentralized applications (dApps)

OpenAI and 100+ companies warn AI-powered cyberattacks are imminent

Aug 27, 2026 · 6 sources

CrowdStrike and Okta surge on earnings as AI threats boost cybersecurity spending

Aug 26, 2026 · 6 sources

Bill Gates warns AI has crossed danger thresholds and calls for urgent policy action

Aug 26, 2026 · 6 sources

Chinese hackers integrate DeepSeek and open-source AI models into cyberattacks

Aug 24, 2026 · 2 sources

Story comments

Loading comments…

Related entities

Ethereum

Topics

Decentralized applications (dApps)Hardware wallet vulnerabilitiesEthereumEthereum walletsAI security

Featured stories

View more in Decentralized applications (dApps)

OpenAI and 100+ companies warn AI-powered cyberattacks are imminent

Aug 27, 2026 · 6 sources

CrowdStrike and Okta surge on earnings as AI threats boost cybersecurity spending

Aug 26, 2026 · 6 sources

Bill Gates warns AI has crossed danger thresholds and calls for urgent policy action

Aug 26, 2026 · 6 sources

Chinese hackers integrate DeepSeek and open-source AI models into cyberattacks

Aug 24, 2026 · 2 sources