Ledger has fixed a bug in certain transparent transaction signing scenarios in the Ethereum application. This was reported by the company's CTO, Charles Guillemet.
There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.
— Charles Guillemet (@P3b7_) August 23, 2026
There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability...
The top manager clarified that the issue was discovered by the Donjon division using a set of AI tools for vulnerability research. The fix has already been deployed in version 1.22.2.
According to Guillemet, users with up-to-date firmware and application patches are fully protected.
The vulnerability was related to the processing of flows in the Ethereum application's APDU commands. In such a scenario, a malicious smart contract could theoretically substitute transaction data at the moment of signing.
For example, a user might think they are approving a small transfer, while in fact authorizing unlimited access for the attacker's address.
Guillemet specifically criticized the public disclosure of the issue. According to him, the external company requested a bounty after the fix was released, did not discuss the case with the program team, and then published a thread from which one could conclude that the problem was not resolved.
For instance, an X user under the pseudonym TestMachine detailed the potential mechanics of transaction substitution.
The Ledger CTO called the situation "a violation of the principles of responsible vulnerability disclosure."
Recall that on August 13, the hardware wallet manufacturer Trezor reported a leak of personal data of 13,689 users. The cause was a hack of its logistics partner ShipMonk.
end-content







