Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
A recently highlighted vulnerability in Ledger’s Ethereum application for its hardware wallets has drawn attention in the cryptocurrency community. The issue involved a race condition in certain clear-signing processes. In these flows, users review human-readable transaction details on the device screen before approving them.
Security researchers described how a malicious decentralized application with appropriate access could send competing commands during the review window.
This potentially allowed the data held in memory for signing to be replaced without refreshing the on-screen display.
As a result, a user might approve what appeared to be a routine small transfer while the device actually signed a different action, such as an unlimited token approval directed to an attacker-controlled address.
The flaw related to the handling of Application Protocol Data Unit commands between the connected software and the device’s Ethereum app.
Validation of the substitution path was publicly demonstrated on a Ledger Flex model, with suggestions that shared code architecture could extend relevance to other devices including Nano X, Nano S Plus, Stax, and Apex variants.
No confirmed cases of funds lost through exploitation of this specific issue had been reported as of late August 2026, and private keys themselves were not at risk of extraction.
Ledger’s internal security research group, known as Donjon, identified the problem using artificial-intelligence-assisted tools and prepared a remedy.
The company released Ethereum application version 1.22.2 around August 12, 2026.
The associated changelog noted security issues in general terms without a detailed public advisory or bulletin at the time of release.
The update introduced safeguards against signing-session replacement and mismatched approval callbacks.
Public discussion intensified between approximately August 21 and 23 when the firm TestMachine, employing its Azimuth autonomous scanning system, shared findings about the race condition.
The disclosure outlined the potential for transaction substitution during review and noted that the fix had not been widely communicated to users in advance of the public posts.
TestMachine indicated it had contacted Ledger’s bounty program, though accounts of the timing and coordination differ.
Ledger executives responded firmly.
Chief Technology Officer Charles Guillemet stated that the company’s own team had already located and addressed a bug affecting certain clear-signing flows roughly two weeks earlier.
He characterized circulating claims as fear, uncertainty, and doubt promoted by an outside group, asserting that users running current firmware and applications were protected.
Guillemet further criticized the manner of disclosure, suggesting it created unnecessary alarm after the patch was available and did not follow responsible verification and coordination practices.
He emphasized the value of artificial intelligence tools for improving security only when paired with disciplined processes that prioritize responsible notification over public noise.
Ledger has advised owners to update their Ethereum app to version 1.22.2 or newer through Ledger Live, along with keeping device firmware and related software current.
The episode underscores ongoing challenges in hardware-wallet security, particularly around clear signing intended to give users transparency over what they authorize.
It also highlights tensions between rapid internal patching and external public disclosures in an environment where artificial intelligence accelerates both vulnerability discovery and defensive research. Users are encouraged to maintain vigilance with software updates and careful verification of all transaction details on their devices.
Source: www.crowdfundinsider.com
