Ledger Ethereum Signing Flaw Was Already Fixed, CTO Says

1 hour ago 3 sources neutral

Key takeaways:

  • Ledger's patched flaw highlights how security disclosure disputes can erode hardware wallet trust.
  • No thefts reported, but delayed user updates remain the real risk for ETH holders.
  • Watch Ledger's response timeline; transparency disputes often trigger short-term DeFi sentiment shifts.

Ledger’s Chief Technology Officer Charles Guillemet said on Aug. 23 that a vulnerability affecting certain clear signing flows in the company’s Ethereum application was already patched before another security firm publicly disclosed the issue. He described online alarm over the finding as “manufacturing fear for attention” and said users with current firmware and applications are protected.

The issue was reported by TestMachine, the security company behind the Azimuth artificial intelligence research tool. According to TestMachine, a malicious application could allegedly send a competing command while a user was still reviewing the original transaction. The reported flaw involved Application Protocol Data Unit communication between the connected application and Ledger’s Ethereum app, potentially allowing one transaction to be displayed while another was prepared for signing.

Clear signing is designed to show transaction details in a readable format on a Ledger device before approval, letting users verify amounts, addresses and smart contract actions. TestMachine said the vulnerability could undermine that process, possibly allowing a limited transaction to be replaced with a broader token approval. The company said Azimuth found the issue during an autonomous scan and validated it on a Ledger Flex, adding that shared code made other models potentially relevant, including Nano X, Nano S Plus, Stax and Apex.

Guillemet disputed the disclosure timeline. He said Ledger Donjon, the company’s internal security research team, discovered the bug using an AI-powered vulnerability research system and deployed the fix approximately two weeks before his statement. He also said TestMachine contacted Ledger’s bounty program after the fix had already shipped, while TestMachine said it shared and verified the finding with Ledger but declined a bounty. Ledger’s public Ethereum application repository shows several August security-related changes involving signing states, application context handling and message finalization, though the records do not clearly identify which change corresponds to the disclosed issue.

No confirmed thefts tied to this specific signing vulnerability had surfaced by Aug. 24, 2026. Ledger users were advised to update Ledger Wallet software, device firmware and the Ethereum app, since updating only the desktop or mobile interface may not replace an outdated application on the hardware device. Ledger has not announced any compensation process, emergency transaction suspension or asset migration related to the Ethereum app issue. The incident differs from the previously reported Zilliqa signing flaw that exposed private keys.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.