Ledger fixed a vulnerability affecting certain clear signing flows in its Ethereum application before another security company disclosed the issue publicly, Chief Technology Officer Charles Guillemet said on Aug. 23.
Summary
- Ledger says its Ethereum app patch fixed vulnerable clear signing flows before public disclosure occurred.
- TestMachine claims a malicious application could replace transaction data while users reviewed Ledger device screens.
- Ledger’s chief technology officer Charles Guillemet says updated firmware and applications protect affected users now.
- No confirmed thefts tied to this specific signing vulnerability had surfaced by August 24, 2026.
- Ledger’s public repository shows continuing security fixes, but does not identify every deployed patch clearly.
Guillemet said Ledger Donjon, the company’s internal security research team, discovered the bug using an artificial intelligence vulnerability research system. Ledger deployed the fix approximately two weeks before his statement, according to his post.
Users with current Ledger firmware and applications are protected, Guillemet said. No independently verified reports of funds stolen through this specific vulnerability had emerged by Aug. 24.
Ledger Ethereum app bug affected clear signing
Clear signing is intended to show transaction details in a readable format on a Ledger device before the user approves them. It allows users to check amounts, addresses and smart contract actions instead of authorizing an unreadable transaction hash.
TestMachine, the security company behind the Azimuth artificial intelligence research tool, said the vulnerability could undermine this review process. According to the company’s public thread, a malicious application could allegedly send a competing command while a user was still reviewing the original transaction.
The reported issue involved Application Protocol Data Unit communication between the connected application and Ledger’s Ethereum app. TestMachine claimed this could let an attacker replace an expected transaction with another action before the user completed approval.
Under that scenario, a device could display one transaction while preparing another for signing. One possible result described by researchers involved replacing a limited transaction with a broader token approval.
Ledger acknowledged that a bug existed in “certain clear signing flows.” However, Guillemet did not publish a detailed technical description, affected version list or security advisory explaining the full attack requirements.
Ledger and TestMachine dispute the disclosure timeline
TestMachine said its Azimuth system found the issue during an autonomous scan and validated it on a Ledger Flex. The company also claimed that shared code made other models potentially relevant, including Nano X, Nano S Plus, Stax and Apex devices.
Those statements remain the company’s account of its research. A complete public proof of concept demonstrating fund theft across every named device was not available at publication time.
Guillemet disputed how the disclosure was presented. He said TestMachine contacted Ledger’s bounty program after the company had already shipped its fix. He further alleged that the researchers did not discuss the issue with Ledger’s bounty team before publishing claims that suggested it remained unresolved.
“It was fixed and deployed two weeks ago,” Guillemet said. He described claims that the problem remained active as “manufacturing fear for attention.” TestMachine, by contrast, said it shared and verified the finding with Ledger but declined a bounty.
Ledger’s public Ethereum application repository shows several security-related changes during August. These include fixes involving signing states, application context handling and message finalization. The available records do not clearly identify which change corresponds to the disclosed clear signing issue or confirm the precise deployment date across Ledger’s device application store.
Users should update firmware and the Ethereum app
Ledger users should update the Ledger Wallet software, device firmware and installed Ethereum application. Updating only the desktop or mobile interface may not replace an outdated application running on the hardware device.
Users should also verify transaction details directly on the secure device screen. Ledger’s guide warns that blind signing remains risky because the device cannot present every smart contract action in a readable format.
As previously reported, Ethereum introduced human readable transaction summaries through the ERC-7730 standard. Ledger helped develop the system before stewardship moved to the Ethereum Foundation.
The latest incident differs from the previously reported Zilliqa signing flaw that exposed private keys. Zilliqa said that vulnerability affected its own native Ledger application and could not be corrected for keys already exposed through recorded signatures.
Ledger has not announced any compensation process, emergency transaction suspension or asset migration related to the Ethereum app issue. Further confirmation would require a technical advisory naming the affected versions, patched release and precise conditions needed to exploit the flaw.
Source link
Author

- Ytv Market News
- Share-market news writer and analyst with deep experience covering equities, commodities, forex, and cryptocurrencies for readers in the USA, UK, Canada, and Australia. Ytv Market News delivers timely market updates, practical trading insights, and clear explanations of macro and company-level catalysts that move prices. Combines on-the-ground financial reporting with technical analysis, using concise charts and actionable ideas to help investors and traders make smarter decisions.
Latest entries
Investing InsightsAugust 24, 202660% of Employees Conceal AI Use, Highlighting Risks of Confidential Information Leaks — BigGo Finance
GermanyAugust 24, 2026Oil falls as US prepares to unveil new Iran sanctions
JapanAugust 24, 2026Departure tax revenue diverted to bear, sakura pest control
Crypto NewsAugust 24, 2026Ethereum Tops $2,300 As Exchange Reserves Keep Falling
