Ledger has eliminated a vulnerability in the Ethereum application

cryptonews.ruPublished on 2026-08-24Last updated on 2026-08-24

Abstract

Ledger has patched a vulnerability in its Ethereum application related to certain clear signing transaction flows. The bug, found by Ledger's internal security team Donjon using AI-powered tools, was fixed in app version 1.22.2. The issue involved the processing of APDU command flows, where a malicious smart contract could theoretically trick the user interface and substitute transaction data during signing. For instance, a user might believe they were approving a small transfer while actually granting unlimited access to an attacker's address. Ledger's CTO Charles Guillemet stated that users with updated firmware and apps are fully protected. He criticized a third-party security company for its public disclosure of the bug after the patch was already released, calling it a violation of responsible disclosure principles. The company allegedly requested a bounty post-fix without prior discussion with Ledger's bug bounty program. The report follows recent news of a data breach at hardware wallet competitor Trezor, where a logistics partner was hacked.

Ledger has fixed a bug in certain transparent transaction signing scenarios in the Ethereum application. This was reported by the company's CTO, Charles Guillemet.

There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.

There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability...

— Charles Guillemet (@P3b7_) August 23, 2026

The top manager clarified that the issue was discovered by the Donjon division using a set of AI tools for vulnerability research. The fix has already been deployed in version 1.22.2.

According to Guillemet, users with up-to-date firmware and application patches are fully protected.

The vulnerability was related to the processing of flows in the Ethereum application's APDU commands. In such a scenario, a malicious smart contract could theoretically substitute transaction data at the moment of signing.

For example, a user might think they are approving a small transfer, while in fact authorizing unlimited access for the attacker's address.

Guillemet specifically criticized the public disclosure of the issue. According to him, the external company requested a bounty after the fix was released, did not discuss the case with the program team, and then published a thread from which one could conclude that the problem was not resolved.

For instance, an X user under the pseudonym TestMachine detailed the potential mechanics of transaction substitution.

The Ledger CTO called the situation "a violation of the principles of responsible vulnerability disclosure."

Recall that on August 13, the hardware wallet manufacturer Trezor reported a leak of personal data of 13,689 users. The cause was a hack of its logistics partner ShipMonk.

end-content

Trending Cryptos

Related Questions

QWhat was the vulnerability that Ledger fixed in their Ethereum app?

AThe vulnerability involved a bug in certain clear signing flows, specifically in the processing of APDU commands within the Ledger Ethereum app. This bug could theoretically allow a malicious smart contract to substitute transaction data at the moment of signing.

QWho discovered the vulnerability in the Ledger Ethereum app and how was it found?

AThe vulnerability was discovered by Ledger's Donjon division using a set of AI-powered vulnerability finding tools.

QWhat specific criticism did Ledger's CTO, Charles Guillemet, express regarding the public disclosure of this issue?

ACharles Guillemet criticized it as a 'violation of the principles of responsible vulnerability disclosure.' He stated that an external company requested a bounty after the fix was already released, did not discuss the case with the bug bounty program team, and then published a thread that could lead users to believe the problem was still unresolved.

QWhat is a potential consequence for a user if the vulnerability had been exploited?

AA user could have thought they were confirming a small transaction while in reality approving unlimited access for an attacker's address.

QWhat unrelated security incident concerning a different hardware wallet manufacturer is mentioned at the end of the article?

AThe article mentions that on August 13th, hardware wallet manufacturer Trezor reported a personal data leak of 13,689 users due to a hack of its logistics partner, ShipMonk.

Related Reads

Besu Patches Vulnerabilities in 5 Components: What Node Operators Need to Know

The Ethereum client Besu, developed by the Hyperledger community, has patched five security vulnerabilities discovered by blockchain security firm CertiK. These vulnerabilities, detailed in four security advisories on August 14, were all addressed in version 26.7.1, an urgent security update initially released on July 27. The intentional delay between the patch release and the public disclosure of details gave node operators a crucial window to update. JiaLiang Chang, CertiK's Director of Security Engineering, explained this "patch first, details later" model provides defenders a time advantage, allowing them to identify affected systems, test the update, and coordinate deployments—particularly important for institutional or permissioned blockchain networks requiring formal change management. The vulnerabilities, found through CertiK's "Chain Scan" attack methodology, involved issues in block announcement handling, consensus proposal buffering, WebSocket subscription limits, and JSON-RPC filter creation. If exploited, they could have allowed an attacker to exhaust a node's memory or thread resources, compromising its availability and the consensus process. Chang highlighted that while the open-source ecosystem is moving toward more formalized security testing (like differential fuzzing and bug bounty programs), coverage remains uneven. Testing often focuses more on protocol compliance than on continuous resource exhaustion, race conditions, or deployment-specific failures. He emphasized that third-party research remains vital for uncovering attack vectors beyond routine development, advocating for a mature, cumulative security model combining continuous integration, multi-node attack testing, independent audits, and regression testing for each confirmed vulnerability.

cryptonews.ru7m ago

Besu Patches Vulnerabilities in 5 Components: What Node Operators Need to Know

cryptonews.ru7m ago

Hack of Term Finance: Attacker Withdraws $8.5 Million Through Governance System Vulnerability

Decentralized lending protocol Term Finance lost $8.5 million due to an exploit of its governance mechanism, not a smart contract hack. The attacker manipulated the low voter turnout in the Meta Vaults system. By depositing just 0.5 ETH, they received a token (tmvETH) representing a share in the vault. Most users did not convert this token into a separate voting token (gtmvETH). The attacker did, gaining control of 90.66% of the issued voting power despite owning only 0.017% of the vault's capital. The attacker created a legitimate governance proposal to disable the 7-day withdrawal timelock and add their own contract to receive user funds. The proposal, publicly viewable for about 145 hours, passed due to a quorum requirement of only 5% and simple majority rule. After voting ended on August 23, 2026, the proposal was executed, allowing the immediate theft of 2,841 WETH and 1.68 million USDC (later swapped for DAI) from several vaults. The incident highlights systemic risks in decentralized governance when voting rights are separated from economic stake and low participation thresholds exist. Security mechanisms like timelocks were ineffective as the attacker could disable them from within the proposal itself. In response, Term Labs irrevocably closed all Meta Vaults and revoked DAO roles. The core lending protocol remained unaffected. The attack underscores the need for governance designs where security parameters are protected from modification through ordinary proposals.

cryptonews.ru7m ago

Hack of Term Finance: Attacker Withdraws $8.5 Million Through Governance System Vulnerability

cryptonews.ru7m ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

活动图片