Late August 2026, a heated dispute pitted Ledger against cybersecurity firm TestMachine over a vulnerability in the French hardware wallet maker’s Ethereum application. CTO Charles Guillemet insists a patch had already shipped before any public disclosure, but the absence of an official security advisory continues to fuel skepticism among users and the broader crypto community.
🔑 Key Takeaways
- A race condition bug affected the clear signing flow of Ledger’s Ethereum app.
- The fix shipped in version 1.22.2 on August 12, 2026, before public disclosure.
- CTO Charles Guillemet accused TestMachine of trying to create fear for attention.
- Donjon did not issue a numbered security bulletin for this specific flaw.
- Ledger urges users to update the Ethereum app on the physical device itself, not just Ledger Live.
Inside the vulnerability
The bug sat in Ledger’s so-called clear signing flow, a mechanism that displays transaction details in a human-readable form on the device’s secure screen instead of raw hexadecimal data. According to TestMachine, a malicious website could send a second command to the device while the user was still reviewing the details of the first transaction.
The technical root cause was a race condition on APDU commands (Application Protocol Data Units, the protocol used to communicate between host software and the Ethereum app running on the secure element). A malicious decentralized application (dApp) could effectively swap a legitimate transaction for another during the signing process. A user could believe they were approving a small transfer while in reality granting an unlimited token allowance to an attacker-controlled address.
« Then they published a thread implying the issue isn’t resolved. It is. This isn’t security research. It’s fear-mongering for attention. »
Charles Guillemet, CTO of Ledger
To gauge the stakes, Chainalysis estimates that approval phishing attacks have caused roughly $1 billion in losses since May 2021, making it one of the most lucrative attack vectors in the crypto landscape.

Ledger’s CTO fires back
Charles Guillemet responded publicly on X on August 23, 2026. He said the vulnerability had been discovered internally by the Donjon team, Ledger’s offensive research lab, using AI tools purpose-built for vulnerability research. According to him, the patch was rolled into version 1.22.2 of the Ethereum app, released on August 12, about ten days before TestMachine published its findings.
The CTO accused TestMachine of failing to follow responsible disclosure principles. He claimed the firm contacted Ledger’s bug bounty program after the patch had shipped, without ever engaging meaningfully with the dedicated team. For its part, TestMachine said it discovered the flaw through its own AI agent, Azimuth, during an autonomous scan, validated it on a Ledger Flex, and then declined any reward from the bug bounty program.
TestMachine also claimed that the shared code base could leave other Ledger models exposed, including the Nano X, Nano S Plus, Stax, and Apex. These claims have not been independently verified by a third party.
A communication gap that fuels criticism
Several details have fed the community’s frustration. The 1.22.2 changelog merely noted « Security issues » without elaboration. No numbered security advisory was issued by the Donjon team for this specific flaw, even though the team has already published 22 such bulletins in the past.
| Date | Event |
|---|---|
| Before Aug 12, 2026 | Flaw discovered internally by the Donjon team |
| Aug 12, 2026 | Version 1.22.2 ships with the patch |
| Aug 22, 2026 | TestMachine contacts the bug bounty after the fix |
| Aug 23, 2026 | Charles Guillemet’s reply on X blaming TestMachine |
| Late Aug 2026 | TestMachine publishes its detailed findings on X |
| Aug 24, 2026 | No verified reports of stolen funds as of this date |
Users pressed Guillemet under his own post, asking for a formal customer-facing notice about this critical update. No verified report of funds stolen through this specific vulnerability had emerged as of August 24, 2026. With Ledger having shipped more than 7 million devices across 180 countries, the communication gap carries outsized weight.
The clear signing stakes for Ledger
The vulnerability hits a strategic nerve. Ledger has invested heavily in making clear signing a default feature, including prior work on the ERC-7730 standard aimed at normalizing how transaction data is displayed on hardware wallets. Ledger helped shape the standard before stewardship was handed off to the Ethereum Foundation.
The episode also lands on top of other Ledger security alerts in recent months, notably cases of fake signers linked to the Recover service. A separate incident involving Ledger’s native Zilliqa app reportedly exposed private keys after about five transactions, though that is a distinct vulnerability with no direct link to the Ethereum flaw.
What Ledger users should do
- Check your Ethereum app version in Ledger Live and confirm it is on 1.22.2 or later.
- Update the app on the physical device itself, not just the Ledger Live interface on desktop or mobile.
- Always read transaction details directly on the device’s secure screen before signing.
- Avoid blind signing (signing unreadable data) when possible, as the device cannot always decode every smart contract action in a readable format.
- Revoke old token allowances using tools like revoke.cash to shrink your attack surface.
Conclusion
The episode highlights the structural tension between external security labs and hardware wallet vendors in a market where trust outweighs the device itself. Shipping a patch before disclosure is a clear positive for Ledger, yet the lack of a numbered security bulletin and proactive communication left a vacuum that TestMachine was quick to fill. Over the medium term, broader adoption of the ERC-7730 standard and more transparent Donjon bulletins could ease this friction, provided both sides agree on a clear disclosure timeline.
For users, the playbook is unchanged: keep device firmware and apps up to date, review every transaction on the secure screen, and minimize blind signing. In an industry where $1 billion has been lost to approval attacks since 2021, these habits remain the first line of defense.
Sources
- CryptoAst — Ledger dément une faille critique sur son app Ethereum
- Crypto Briefing — Ledger Ethereum app vulnerability fix
- CryptoNews — Ledger security
- BeInCrypto — Zilliqa and Ledger
- CoinAcademy — Ledger faille critique
- GitHub LedgerHQ/app-ethereum
This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

