Ledger has patched a vulnerability in the Ethereum app

cryptonews.ruPublished on 2026-08-24Last updated on 2026-08-24

Abstract

Ledger has patched a bug in the Ethereum application related to certain clear signing transaction flows. The vulnerability, discovered by Ledger's internal Donjon team using AI-powered tools, involved the processing of APDU commands. In a worst-case scenario, a malicious smart contract could have manipulated transaction data during the signing process, potentially tricking a user into approving unlimited access for an attacker's address. The fix has been deployed in version 1.22.2, and users with up-to-date firmware and apps are fully protected. Ledger's CTO Charles Guillemet criticized the public disclosure of the issue by an external security firm, stating it occurred after the patch was released and without prior discussion, constituting a breach of responsible disclosure principles. Separately, the article notes that Trezor recently reported a data leak of 13,689 users due to a hack at its logistics partner.

Ledger has fixed a bug in certain scenarios of clear transaction signing in the Ethereum app. This was announced by the company's CTO, Charles Guillemet.

There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.

There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability...

— Charles Guillemet (@P3b7_) August 23, 2026

The executive clarified that the issue was discovered by the Donjon division using a suite of AI tools for vulnerability detection. The fix has already been deployed in version 1.22.2.

According to Guillemet, users with up-to-date firmware and application patches are fully protected.

The vulnerability was related to the processing of flows in the Ethereum app's APDU commands. In such a scenario, a malicious smart contract could theoretically have substituted transaction data at the moment of signing.

For example, a user might have thought they were confirming a small transfer, while in reality they were approving unlimited access for the attacker's address.

Guillemet separately criticized the public disclosure of the problem. He stated that an external company requested a reward only after the patch was released, did not discuss the case with the program's team, and then published a thread from which one could conclude the problem was not resolved.

For instance, an X user under the pseudonym TestMachine detailed the potential mechanics of transaction substitution.

The Ledger CTO called the situation a "violation of the principles of responsible vulnerability disclosure."

Recall that on August 13, hardware wallet manufacturer Trezor reported a leak of personal data of 13,689 users. The cause was a hack of its logistics partner ShipMonk.

Trending Cryptos

Related Questions

QWhat was the vulnerability in Ledger's Ethereum app and what could it have allowed?

AThe vulnerability was a bug in certain clear signing flows of the Ethereum app, specifically related to the handling of APDU command streams. In this scenario, a malicious smart contract could theoretically substitute transaction data at the moment of signing. For example, a user might think they were approving a small transfer but would actually be granting unlimited access to an attacker's address.

QHow was the vulnerability discovered and fixed by Ledger?

AThe vulnerability was discovered by Ledger's internal security team, Donjon, using their AI-powered vulnerability detection tools. The fix was deployed in version 1.22.2 of the Ethereum app.

QAccording to Ledger's CTO, are users safe from this vulnerability now?

AYes. According to Charles Guillemet, users with updated firmware and the latest version of the applications are fully protected.

QWhat criticism did Ledger's CTO level against the external security company that disclosed the issue?

ACharles Guillemet criticized the company for violating the principles of responsible vulnerability disclosure. He stated that the company requested a bounty after the fix was already released, did not discuss the case with the Ledger program team beforehand, and then published information that could be interpreted as the problem being unsolved.

QHow does the article connect this Ledger incident to news about a competitor, Trezor?

AThe article mentions that earlier in the same month (August 13), the hardware wallet manufacturer Trezor reported a data leak of 13,689 users' personal data. This was due to a breach at their logistics partner, ShipMonk. This serves as a reminder of broader security concerns in the hardware wallet industry beyond just software bugs.

Related Reads

AI Democratizes Hacking, Bitcoin Red Team White Hats Race in Speed-Based Attack-Defense Contest

AI is democratizing powerful hacking tools, putting them in the hands of those with little cybersecurity expertise. Cryptocurrency developers are now in a race to find system vulnerabilities before attackers do. The Bitcoin Red Team, a group of 20-25 volunteers including anonymous developers like Calle, has formed to urgently address these AI-augmented security threats within the Bitcoin ecosystem. Calle emphasizes that while the Bitcoin core protocol itself is secure, the real risk lies in the wallets, applications, services, and other third-party software built on top of it—the software most users interact with. Incidents like the Coldcard wallet hack and the emergence of powerful Chinese AI models have accelerated their proactive security auditing efforts. The team both accepts audit requests from Bitcoin projects and proactively scans major open-source projects. They report found vulnerabilities to developers and refine their classification standards. Notably, Calle states the team frequently uses Chinese AI models over US counterparts, as the latter's strict safety guardrails often block cybersecurity research tasks, hindering their utility for finding or fixing vulnerabilities. Calle warns that AI is erasing the information asymmetry that previously protected some vulnerabilities. It lowers the technical barrier, allowing non-experts to exploit simple flaws. He describes the current state of Bitcoin software as "on fire" and believes the direct financial incentive of cryptocurrency makes it a first target in this industry-wide shift, with other sectors to follow. The era of security through obscurity is over.

marsbit17m ago

AI Democratizes Hacking, Bitcoin Red Team White Hats Race in Speed-Based Attack-Defense Contest

marsbit17m ago

Foreign Capital Sells Off $29 Billion in Short-Term US Treasuries, Why is the US Betting on Stablecoins to "Take Over"?

In June, foreign investors netted $133.5 billion into U.S. financial markets but simultaneously sold $29 billion in short-term U.S. Treasury bills. This divergence highlights a strong preference for U.S. equities over government debt. While overseas buyers purchased $181.4 billion in stocks, demand for Treasuries weakened significantly. This trend explains why the U.S. is looking to stablecoins as a potential new source of demand for its debt. Stablecoin issuers like Tether and Circle back their tokens primarily with highly liquid assets, including short-term Treasuries. As users buy stablecoins, issuers convert that dollar demand into Treasury purchases. Recent U.S. legislative efforts, such as the proposed rules under the *GENIUS Act*, formalize this by mandating stablecoin reserves be held in assets like cash and short-term Treasuries. Currently, stablecoins represent a substantial existing buyer base. For instance, Tether alone held nearly $115 billion in direct T-bill exposure in Q2. However, recent stablecoin supply growth has been minimal and does not account for the $29 billion sell-off by foreign investors in June. For stablecoins to act as a meaningful counterbalance to waning foreign demand, their circulating supply would need to expand significantly. The next TIC report will be crucial to monitor whether foreign selling continues and if stablecoin growth begins to fill the demand gap. Ultimately, the U.S. is strategically positioning the regulated stablecoin sector as a potential new pillar of demand for its government debt.

marsbit18m ago

Foreign Capital Sells Off $29 Billion in Short-Term US Treasuries, Why is the US Betting on Stablecoins to "Take Over"?

marsbit18m ago

Unitree Investors Jointly Heavy Bet on an Embodied Team

Unibot's early investors, including Meituan, Sequoia Capital, and Matrix Partners, have jointly invested in MiaoDong Technology, another humanoid robotics startup. Founded by former DJI employees—CEO Gao Jianrong, a 9-year DJI veteran who led multiple core business units, and CTO Yang Shuo, who previously worked in Tesla's Optimus team—MiaoDong is known for its combined expertise in hardware productization and advanced robotics cognition. Their core strategy centers on in-house motor R&D and full-stack software-hardware capabilities. The company recently made headlines with its first product, Beni, a wheel-legged "camera robot" designed for low-angle, ground-level filming and personal companionship. Successfully launched on Kickstarter, Beni set a record for the highest fundraising amount in the platform's robotics category. It received a perfect 10/10 rating from influential tech reviewer Marques Brownlee (MKBHD). Beni features capabilities like autonomous obstacle avoidance, the ability to jump 25cm, and self-righting after a fall. MiaoDong plans to leverage the technological and user data feedback from Beni's consumer launch to inform the development of future home-use humanoid robots. The company emphasizes a product-first, user-centric approach, prioritizing real-world applications and reliability over rapid, demo-focused scaling. With Beni set for global release in October and an internal target to sell millions of units, MiaoDong aims to establish itself as a significant player in the embodied AI space through steady, product-driven growth.

marsbit32m ago

Unitree Investors Jointly Heavy Bet on an Embodied Team

marsbit32m ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

活动图片