Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
A critical vulnerability that could have allowed hackers to drain a crypto wallet during a single transaction in Ledger’s Ethereum app has been flagged as of August 26.
This design flaw was publicly disclosed around August 23, 2026, by TestMachine, an Artificial Intelligence (AI)-powered security research team. However, the bug was initially found by Ledger’s own internal security team, Donjon, which used AI-powered vulnerability detection tools.
“There was a bug concerning certain clear signing flows. It was found by the Donjon team using their AI-powered vulnerability research suite. It was fixed and deployed two weeks ago. If you keep your Ledger apps up to date, you are protected,” Charles Guillemet, Ledger CTO, stated.
Ledger patched this vulnerability quietly on August 12 with version 1.22.2. Furthermore, this bug allowed malicious decentralized applications (DApps) to swap a harmless transfer for an unlimited token approval, granting backdoor access to all ERC-20 tokens on users’ Ledger hardware wallets.
As of press time, this bug had not been exploited, but Ledger users who have not updated to the latest version remain vulnerable. Although this specific vulnerability may not affect Ledger Nano S users, the company urged all its customers to update to the latest version.
Ledger security issues 2026
So far in 2026, the Ledger team has reported two more severe vulnerabilities. For instance, a more serious bug in Ledger’s Zilliqa app, which had existed since 2019, exposed private keys through flawed random number generation and led to the theft of 683 million ZIL from over 6,700 accounts.
The Zilliqa team first observed suspicious on-chain activity on July 19, 2026, publicly disclosed the vulnerability on July 21, and suspended native ZIL transactions shortly after. This flaw was isolated to the Zilliqa network and did not affect other holdings.
Earlier this year, Ledger’s payment processor Global-e suffered a data breach that exposed customer names and contact information. The notable use of AI by both black-hat and white-hat attackers has significantly changed the software landscape, thus heavy criticism of hardware wallet companies by on-chain sleuth ZachXBT.
Source: finbold.com

1 Comment
Pingback: Hedera DeFi Protocol Bonzo Lend Suffers $8.7 Million Loss from Oracle Flaw – xpertsstudio