TLDR
- Ledger patched a vulnerability in its Ethereum app on August 12, shipping the fix in version 1.22.2 before any public disclosure
- The bug was a race condition that could let a malicious app swap out a legitimate transaction for a harmful one during signing
- Ledger’s internal team, Donjon, found the flaw using AI-assisted tools before any external researcher reported it
- Security researcher TestMachine publicly disclosed the bug between August 21-23, which Ledger CTO Charles Guillemet called “manufacturing fear for attention”
- No confirmed reports of stolen funds linked to this vulnerability had surfaced as of August 24, 2026
Ledger patched a vulnerability in its Ethereum hardware wallet app on August 12, 2026. The fix was included in Ethereum app version 1.22.2. The company said almost nothing publicly until a security researcher forced the issue into the open.
There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.
There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability…
— Charles Guillemet (@P3b7_) August 23, 2026
The bug was a race condition involving APDU commands. APDU stands for Application Protocol Data Unit, which is the communication language between your computer software and the secure chip inside a Ledger device.
During clear signing flows, where the device shows readable transaction details on its screen, a competing malicious command could slip in. This could replace the original transaction with a different one before the user finished approving it.
In a real attack, a user could have believed they were approving a small token transfer. In reality, they may have been authorizing unlimited token access to an attacker’s address.
How the Flaw Was Found
Ledger’s internal security team, known as Donjon, discovered the vulnerability before any outside researcher flagged it. The team used AI-assisted research tools to identify and fix the problem.
The patch was deployed without any public announcement. No security advisory, blog post, or public statement accompanied the fix for roughly ten days.
That changed when a researcher using the name TestMachine publicly disclosed the bug between August 21 and 23. TestMachine described how the race condition worked and said it had validated the flaw on a Ledger Flex device.
TestMachine also said shared code could make other devices relevant, including the Nano X, Nano S Plus, Stax, and Apex. The company said it shared findings with Ledger but declined a bounty offer.
Ledger and TestMachine Disagree on the Timeline
Ledger CTO Charles Guillemet said TestMachine contacted Ledger’s bounty program only after the fix had already shipped. He said the researchers did not engage with Ledger’s bounty team before publishing claims that implied the issue was still active.
Guillemet said the fix had been live for about two weeks before TestMachine went public. He pushed back on the framing of the disclosure, calling it an attempt to generate attention.
TestMachine’s account differs. The company said it independently discovered and validated the bug, then shared it with Ledger. It declined the bounty and chose to publish its findings.
No complete proof of concept demonstrating fund theft across all named devices was publicly available as of the time of reporting.
Ledger’s public Ethereum app repository shows several security-related changes made during August, covering signing states and message finalization. The records do not clearly match a single change to the disclosed flaw.
Ledger users should update their device firmware and the Ethereum app to version 1.22.2 or later. Updating only the desktop or mobile software may not replace an outdated app running on the hardware itself.
Ledger has not announced any compensation process or emergency steps related to this issue as of August 24, 2026.







