Ledger Patched an Ethereum Signing Flaw, Then Fought Over the Disclosure
Ledger shipped a fix for its Ethereum app on 12 August, and the argument started ten days later. Version 1.22.2 closed a race condition that could let a malicious site swap a transaction while the owner was still reading it on the device screen. The screen would keep showing the original. Approving returned a signature over the substituted data. No theft has been reported, and the company says anyone running the current app was never exposed.
What the bug did
The flaw sat in the APDU channel, the command protocol between software on a computer and the app running on the wallet. CryptoSlate's account, the most detailed located, says the channel stayed open during a review, so a second signing command could overwrite the transaction data in memory without refreshing what the display showed. BeInCrypto and crypto.news give the practical version: the owner approves a small transfer and signs an unlimited token approval instead. That second permission is the one that empties an account later, at the attacker's convenience.
Version 1.22.2 blocks new signing sessions while a review is open, and rejects an approval if the app state no longer matches the conditions the signature was meant for. That description of the two safeguards comes from CryptoSlate alone.
Which devices, and how much is confirmed
TestMachine, the AI security firm that published the finding, validated it on a Ledger Flex. Its own post says the same shared APDU and interface code runs on the Nano X, Nano S Plus, Stax and Apex, and every "all models" line in the coverage traces back to that sentence. No outlet located has independent confirmation on the other four devices. Ledger told owners to update Ledger Live, the device firmware and the Ethereum app separately, and to check each transaction on the device before approving it.
The row is about disclosure, not the patch
Charles Guillemet, Ledger's chief technology officer, answered on 23 August. Ledger Donjon, the in-house security team, found the bug itself about two weeks earlier, he said, and the fix was already live when TestMachine went public on 22 August.
"This company reached out to our bounty program after the fix was already shipped, and did not follow responsible disclosure," Guillemet said.
He went further, describing the thread that followed as "manufacturing fear for attention". AMBCrypto and BeInCrypto carry that remark with different words around the same clause, so only the clause itself is quoted here. TestMachine's version is that its Azimuth scanner found the issue during autonomous scanning, that it verified the finding on hardware, and that it declined the bounty. No outlet located reconciles the two discovery accounts. Both can be true at once.
What is not on the record
CoinLaw checked Ledger's public GitHub release feed on 24 August and found no August 2026 tagged release at all; the most recent tag there is 1.22.1, dated 27 May. It also found no security bulletin, no published list of affected versions and no complete public proof of concept. That is one outlet's check, and nothing located contradicts it. Ledger's account and its paper trail have not met yet.
The category of attack is the expensive one. BeInCrypto cites Chainalysis putting roughly $1 billion in losses to approval phishing since May 2021, a figure that appears in that report alone. Two other failures of the signing chain are already on this site's record this summer: a 2021 build error drained 594 BTC from Coldcard wallets in July, and a poisoned release of Injective's software kit harvested seed phrases a month before that. Both cost money. This one has cost none so far, and Ledger has still published no advisory.
Read also: Galaxy Counts at Least Fifteen Attackers in the Coldcard Exploit