Ledger has eliminated a vulnerability in the Ethereum application

cryptonews.ruPublished on 2026-08-24Last updated on 2026-08-24

Abstract

Ledger has patched a vulnerability in its Ethereum application related to certain clear signing transaction flows. The bug, found by Ledger's internal security team Donjon using AI-powered tools, was fixed in app version 1.22.2. The issue involved the processing of APDU command flows, where a malicious smart contract could theoretically trick the user interface and substitute transaction data during signing. For instance, a user might believe they were approving a small transfer while actually granting unlimited access to an attacker's address. Ledger's CTO Charles Guillemet stated that users with updated firmware and apps are fully protected. He criticized a third-party security company for its public disclosure of the bug after the patch was already released, calling it a violation of responsible disclosure principles. The company allegedly requested a bounty post-fix without prior discussion with Ledger's bug bounty program. The report follows recent news of a data breach at hardware wallet competitor Trezor, where a logistics partner was hacked.

Ledger has fixed a bug in certain transparent transaction signing scenarios in the Ethereum application. This was reported by the company's CTO, Charles Guillemet.

There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.

There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability...

— Charles Guillemet (@P3b7_) August 23, 2026

The top manager clarified that the issue was discovered by the Donjon division using a set of AI tools for vulnerability research. The fix has already been deployed in version 1.22.2.

According to Guillemet, users with up-to-date firmware and application patches are fully protected.

The vulnerability was related to the processing of flows in the Ethereum application's APDU commands. In such a scenario, a malicious smart contract could theoretically substitute transaction data at the moment of signing.

For example, a user might think they are approving a small transfer, while in fact authorizing unlimited access for the attacker's address.

Guillemet specifically criticized the public disclosure of the issue. According to him, the external company requested a bounty after the fix was released, did not discuss the case with the program team, and then published a thread from which one could conclude that the problem was not resolved.

For instance, an X user under the pseudonym TestMachine detailed the potential mechanics of transaction substitution.

The Ledger CTO called the situation "a violation of the principles of responsible vulnerability disclosure."

Recall that on August 13, the hardware wallet manufacturer Trezor reported a leak of personal data of 13,689 users. The cause was a hack of its logistics partner ShipMonk.

end-content

Trending Cryptos

Related Questions

QWhat was the vulnerability that Ledger fixed in their Ethereum app?

AThe vulnerability involved a bug in certain clear signing flows, specifically in the processing of APDU commands within the Ledger Ethereum app. This bug could theoretically allow a malicious smart contract to substitute transaction data at the moment of signing.

QWho discovered the vulnerability in the Ledger Ethereum app and how was it found?

AThe vulnerability was discovered by Ledger's Donjon division using a set of AI-powered vulnerability finding tools.

QWhat specific criticism did Ledger's CTO, Charles Guillemet, express regarding the public disclosure of this issue?

ACharles Guillemet criticized it as a 'violation of the principles of responsible vulnerability disclosure.' He stated that an external company requested a bounty after the fix was already released, did not discuss the case with the bug bounty program team, and then published a thread that could lead users to believe the problem was still unresolved.

QWhat is a potential consequence for a user if the vulnerability had been exploited?

AA user could have thought they were confirming a small transaction while in reality approving unlimited access for an attacker's address.

QWhat unrelated security incident concerning a different hardware wallet manufacturer is mentioned at the end of the article?

AThe article mentions that on August 13th, hardware wallet manufacturer Trezor reported a personal data leak of 13,689 users due to a hack of its logistics partner, ShipMonk.

Related Reads

Bitcoin's Record-Breaking Week: Surge Over $16,000 and Predictions for the 'Strongest' Cycle in History

Bitcoin recorded its largest weekly dollar gain in history, surging approximately from $63,000 to $79,000 between August 17 and 23, 2026. Strive CEO Matt Cole noted Bitcoin's explosive breakout not only against the US dollar but also against gold, suggesting the world is entering a period of heightened demand for scarce assets like gold, silver, and Bitcoin. He believes Bitcoin could attract a disproportionate share of new liquidity and anticipates the next market cycle could be the "strongest" in history, though a short-term pullback is possible. Analysts highlighted key factors for continued growth. Zeus Research's Dominic John pointed to new ETF inflows and improving macroeconomic liquidity, with the potential CLARITY Act in September as a positive catalyst. He sees a path to $85,000-$90,000 if Bitcoin reclaims $80,000, with $100,000 possible under favorable conditions. Conversely, BTC Markets' Rachel Lucas warned against attributing the rally to a single factor, noting it likely resulted from short squeezes, spot demand, and derivatives market activity. She advised monitoring spot ETF inflows, open interest, and funding rates. Predominantly spot-driven demand creates a firmer foundation, while overheated funding rates and high open interest signal increased risk of a sharp correction. She added that profit-taking and volatility post-rally are normal and not inherently bearish. The report also recalled that Bitcoin and Ethereum ETFs saw their best weekly inflow of 2026 at $2.62 billion from August 17-21.

cryptonews.ru28m ago

Bitcoin's Record-Breaking Week: Surge Over $16,000 and Predictions for the 'Strongest' Cycle in History

cryptonews.ru28m ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

活动图片