Ledger quietly fixed a serious flaw in its Ethereum app nearly two weeks before anyone outside the company knew it existed, and the way that timeline came to light has turned into its own small controversy. The Ledger Ethereum vulnerability involved a race condition that could have let a malicious application swap a legitimate transaction for a harmful one while a user was still approving it on their device screen. Ledger patched the issue on August 12, 2026, but said almost nothing publicly until a security researcher forced the story into the open more than a week later.
Summary
Key takeaways
- Ledger patched the flaw in its Ethereum app on August 12, 2026, shipping the fix in version 1.22.2 without a public security bulletin.
- The bug was a race condition involving APDU commands that could let a malicious app swap a legitimate transaction during clear signing.
- Ledger’s internal team, Donjon, found the flaw using AI-assisted tools before any outside researcher reported it.
- Security firm TestMachine disclosed the bug publicly between August 21 and 23, 2026, using an AI agent called Azimuth.
- No confirmed reports of stolen funds tied to the flaw had emerged as of August 24, 2026.
Ledger’s Secret Fix of Ethereum App Vulnerability
Ledger’s fix arrived without fanfare on August 12, 2026, buried in a routine software update rather than flagged as a security patch. The change was included in Ethereum app version 1.22.2, and for roughly ten days the company issued no advisory, no blog post, and no public statement explaining what had actually been repaired.
Details of the Patch and Version
Users running the Ethereum app needed to update to version 1.22.2 or later to receive the fix. Ledger has emphasized that updating only the companion desktop or mobile software would not have been enough, since the vulnerable code lived on the app running directly on the hardware device itself.
Nature of the Race Condition Bug
The flaw centered on APDU commands, the technical language that Ledger devices use to communicate between a connected computer and the secure chip that actually signs transactions. Ledger’s core security promise rests on what the company calls clear signing, where the device screen displays readable transaction details so users know exactly what they are approving before confirming it.
The race condition undermined that promise. During clear signing flows, a competing malicious command could slip in and replace the original transaction with a different one before the user finished the approval process. In practice, someone could believe they were confirming a small token transfer while actually authorizing unlimited token access to an attacker’s wallet address.
Discovery and Disclosure Timeline
The gap between Ledger’s silent patch and the public disclosure is where the story gets contentious, with both sides describing a different sequence of events.
Internal Detection by Donjon Using AI Tools
Ledger’s internal security unit, known as Donjon, says it discovered the vulnerability on its own, before any external researcher flagged it. The team relied on AI-assisted research tools to identify and fix the flaw, an approach that reflects a broader shift toward machine-assisted vulnerability hunting inside hardware wallet security teams.
Public Disclosure by Security Researcher TestMachine
That quiet period ended when TestMachine, an AI security firm, published its own findings between August 21 and 23, 2026. TestMachine says it uncovered the bug using an autonomous AI agent called Azimuth, which the firm built specifically to hunt exploits in smart contracts. On the company’s own EVMBench benchmark, Azimuth reportedly catches 86.3% of known bugs with roughly 2.7% false positives.
In its disclosure, TestMachine wrote that the flaw was “found by Azimuth during an autonomous scan of the Ledger Ethereum app,” adding that it had been “validated on Flex,” “shared and verified with the team,” while the firm was “declining any bounty.” TestMachine also pointed to shared APDU and UI code across the Nano X, Nano S Plus, Stax, and Apex, suggesting the underlying issue could extend beyond the Flex device it tested.
Ledger’s Response and Dispute
Ledger CTO Charles Guillemet pushed back hard on how the disclosure was framed. He said TestMachine only contacted Ledger’s bounty program after the fix had already shipped, and that the fix had already been live for about two weeks by the time the researchers went public. Guillemet accused TestMachine of manufacturing fear for attention rather than practicing responsible security research, arguing the public framing implied the bug was still active when it had already been resolved.
TestMachine’s account differs on the sequence. The firm maintains it independently discovered and validated the bug, shared its findings with Ledger, declined the bounty offer, and then chose to publish. Ledger’s public Ethereum app repository shows several security-related changes made throughout August covering signing states and message finalization, though the available records do not clearly isolate a single change tied to this specific flaw.
Security Impact and User Guidance
For everyday Ledger users, the most important number in this story is simple: no confirmed reports of stolen funds linked to the vulnerability had surfaced as of August 24, 2026. That does not mean the risk was theoretical. A working exploit could have let an attacker rewrite the terms of a transaction a user thought they were approving, turning a routine token transfer into unlimited access for a malicious address.
No complete proof of concept demonstrating actual fund theft across all the named devices was publicly available at the time of reporting, and Ledger has not released a formal security advisory or announced any compensation process tied to the incident. That silence is itself part of the story. A patch shipped quietly and without a public bulletin leaves users to piece together risk from third-party disclosures rather than from the manufacturer directly.
Ledger has advised users to update both their device firmware and the Ethereum app to version 1.22.2 or later, noting that updating desktop or mobile companion software alone will not replace an outdated app on the hardware wallet itself. Given that TestMachine flagged shared code across the Flex, Nano X, Nano S Plus, Stax, and Apex lines, keeping every connected device current remains the most direct safeguard available to users right now.
This episode also underscores why the discovery method matters as much as the fix itself. Donjon’s use of AI-assisted tools to catch the flaw before any outsider did shows how automated scanning is becoming part of the internal defense layer at hardware wallet makers. At the same time, TestMachine’s use of its own AI agent to independently find and disclose the same class of bug within weeks raises a pointed question for the industry: if AI tools can now surface these flaws from both inside and outside a company almost simultaneously, disclosure timing and transparency practices may need to catch up just as fast as the tooling has.
FAQ
What was the security flaw in Ledger’s Ethereum app?
It was a race condition involving APDU commands that could allow a malicious app to swap legitimate transactions with harmful ones during signing.
How and when was the vulnerability discovered by Ledger?
Ledger’s internal security team Donjon found the flaw using AI-assisted tools before any external researcher reported it.
When was the vulnerability publicly disclosed?
Security researcher TestMachine publicly disclosed the bug between August 21 and 23, 2026.
Is there any evidence funds were stolen due to this vulnerability?
No confirmed reports of stolen funds linked to this vulnerability had appeared as of August 24, 2026.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

