Ledger has fixed a bug in certain scenarios of clear transaction signing in the Ethereum app. This was announced by the company's CTO, Charles Guillemet.
There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.
— Charles Guillemet (@P3b7_) August 23, 2026
There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability...
The executive clarified that the issue was discovered by the Donjon division using a suite of AI tools for vulnerability detection. The fix has already been deployed in version 1.22.2.
According to Guillemet, users with up-to-date firmware and application patches are fully protected.
The vulnerability was related to the processing of flows in the Ethereum app's APDU commands. In such a scenario, a malicious smart contract could theoretically have substituted transaction data at the moment of signing.
For example, a user might have thought they were confirming a small transfer, while in reality they were approving unlimited access for the attacker's address.
Guillemet separately criticized the public disclosure of the problem. He stated that an external company requested a reward only after the patch was released, did not discuss the case with the program's team, and then published a thread from which one could conclude the problem was not resolved.
For instance, an X user under the pseudonym TestMachine detailed the potential mechanics of transaction substitution.
The Ledger CTO called the situation a "violation of the principles of responsible vulnerability disclosure."
Recall that on August 13, hardware wallet manufacturer Trezor reported a leak of personal data of 13,689 users. The cause was a hack of its logistics partner ShipMonk.








