Ledger Fixed a Secret Ethereum Flaw Two Weeks Before Anyone Knew It Existed
TLDR
- Ledger patched a vulnerability in its Ethereum app on August 12, shipping the fix in version 1.22.2 before any public disclosure
- The bug was a race condition that could let a malicious app swap out a legitimate transaction for a harmful one during signing
- Ledger’s internal team, Donjon, found the flaw using AI-assisted tools before any external researcher reported it
- Security researcher TestMachine publicly disclosed the bug between August 21-23, which Ledger CTO Charles Guillemet called “manufacturing fear for attention”
- No confirmed reports of stolen funds linked to this vulnerability had surfaced as of August 24, 2026
Ledger patched a vulnerability in its Ethereum hardware wallet app on August 12, 2026. The fix was included in Ethereum app version 1.22.2. The company said almost nothing publicly until a security researcher forced the issue into the open.
There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.
… Continue reading the full article at the original source below.
This content is automatically aggregated. Full credit goes to the original publisher (coincentral.com).


