Ledger Ethereum Vulnerability Sparks Dispute Over Secret Patch Timeline

Ledger quietly fixed a serious flaw in its Ethereum app nearly two weeks before anyone outside the company knew it existed, and the way that timeline came to light has turned into its own small controversy. The Ledger Ethereum vulnerability involved a race condition that could have let a malicious application swap a legitimate transaction for a harmful one while a user was still approving it on their device screen. Ledger patched the issue on August 12, 2026, but said almost nothing publicly until a security researcher forced the story into the open more than a week later.
Key takeaways
- Ledger patched the flaw in its Ethereum app on August 12, 2026, shipping the fix in version 1.22.2 without a public security bulletin.
- The bug was a race condition involving APDU commands that could let a malicious app swap a legitimate transaction during clear signing.
- Ledgerโs internal team, Donjon, found the flaw using AI-assisted tools before any outside researcher reported it.
- Security firm TestMachine disclosed the bug publicly between August 21 and 23, 2026, using an AI agent called Azimuth.
- No confirmed reports of stolen funds tied to the flaw had emerged as of August 24, 2026.
Ledgerโs Secret Fix of Ethereum App Vulnerability
Ledgerโs fix arrived without fanfare on August 12, 2026, buried in a routine software update rather than flagged as a security patch. The change was included in Ethereum app version 1.22.2, and for roughly ten days the company issued no advisory, no blog post, and no public statement explaining what had actually been repaired.
โฆ Continue reading the full article at the original source below.


