Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Add to Google Preferred Sources
Hardware wallet maker Ledger patched a security vulnerability discovered in the clear-signing process of its Ethereum app, but only disclosed it roughly two weeks later, igniting debate in the security community over disclosure timing. Ledger CTO Charles Guillemet stated that the company’s in-house security team, Ledger Donjon, discovered the flaw and completed remediation, and that users keeping their firmware and apps up to date are protected. The vulnerability is confined to the Ethereum app software—not the hardware itself. The core issue is not whether funds were lost, but the delayed disclosure after the patch. Guillemet alleged that an external security firm disclosed the vulnerability after the patch was deployed while implying it remained unresolved. Users are advised to keep the Ethereum app updated to the latest version via Ledger Live.
Key Elements

Hardware wallet maker Ledger patched a security vulnerability discovered in certain signing processes of its Ethereum (ETH) app, but only disclosed it belatedly—sparking a debate within the security industry over the timing of vulnerability disclosure.
Ledger CTO Charles Guillemet said on the 24th (local time) that the company’s in-house security research team, Ledger Donjon, discovered a vulnerability in part of the clear-signing process of the Ethereum app and completed remediation approximately two weeks ago. Clear signing is a feature that allows users to review transaction details—such as the recipient or amount—in a human-readable format before signing a blockchain transaction.
The vulnerability is confined to the Ethereum app, a software component that Ledger devices use to sign and display Ethereum transactions—not the Ledger device hardware itself. The Ethereum app is maintained in Ledger’s open-hardware wallet’s security model. As such, this disclosure should not be interpreted as a breach of Ledger device security overall
Ledger Donjon documented the affected behavior and corresponding fixes on its internal security bulletin. Guillemet explained that users who keep their Ledger device firmware and related applications up to date are protected from this vulnerability.
He also raised concerns about how an external security firm handled its disclosure. According to Guillemet, a company describing itself as a “smart contract security” firm disclosed the vulnerability after Ledger’s patch deployment was complete, yet subsequently implied the issue remained unresolved.
Patch First, Disclosure Later
The crux of this matter is not whether funds were lost, but the timing of disclosure. According to publicly available materials, the issue was already patched before it became widely known to the public. A quiet fix was followed by a belated disclosure.
According to reporting by BeInCrypto, the handling of this bug escalated into a debate over how and when flaws should be disclosed to users after a patch has been deployed. Exact dates and patched versions have not been confirmed, and users seeking to verify the patched build are advised to check version history and release notes on Ledger’s official app repository rather than relying on secondary summaries.
Delayed disclosure is a critical issue in security reporting. Users unaware that a flaw existed cannot assess whether they were exposed before updating. A silent patch closes the hole, but fails to provide the community with the context needed to evaluate risk—a friction this case has laid bare.
One security researcher actively voiced opinions on the matter on X (formerly Twitter), fueling the debate over the disclosure approach.
What Users Should Check
The practical response is straightforward: verify that the Ethereum app is running the latest version through Ledger Live, Ledger’s official update channel.
This incident comes at a time when Ethereum has established itself as a central axis for institutional capital flows. Recently, spot Bitcoin and Ethereum ETFs recorded weekly inflows of $2.3 billion (approximately 3.2 trillion won)—the largest since October of last year—and Ethereum had previously hit an all-time high. As more capital settles into Ethereum, including institutional DeFi collateral, trust in the wallet layer has emerged as a critical factor.
The core of this incident is a matter of transparency, not a confirmed breach. Users who keep their Ethereum app up to date are following guidance supported by currently available evidence.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
Source: finance.biggo.com
