Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Ledger Fixes Ethereum App Flaw that Could Bypass Clear-Signing Protections

Ledger Fixes Ethereum App Flaw that Could Bypass Clear-Signing Protections

By: Jordan Vector Cybersecurity Expert

Last updated: August 25, 2026

Human Written
Ledger Fixes Ethereum App Flaw that Could Bypass Clear-Signing Protections
  • Ledger says it fixed a flaw in certain Ethereum clear-signing flows before the issue became public.

  • TestMachine says the bug could let a malicious app replace transfer data during user approval.

  • Ledger urges users to update device firmware and apps. The company says updated users are safe.

Ledger has pushed back against reports of a flaw in its Ethereum app, saying the issue was fixed before it became public. Charles Guillemet, Ledger’s chief technology officer, said on August 23 that Ledger Donjon found the bug during internal testing. He said Donjon used AI-powered tools to find the problem.

Guillemet said Ledger fixed and sent out the patch about two weeks earlier. He also said users with current firmware and apps are safe.

The dispute began after security firm TestMachine described a similar flaw in public posts. TestMachine said its Azimuth AI system found the issue during an automated scan of Ledger’s Ethereum app.

Ledger says TestMachine contacted its bug bounty program after the fix had shipped. Guillemet also accused the company of making the issue look unresolved.

The Bug Affected Clear Signing

The issue involved Ledger’s clear-signing process. Clear signing helps users read transfer details before they approve them. A supported Ledger device can show details such as the recipient, amount and contract action.

That screen is a key safety check. Users can compare what they expect to approve with what the device shows.

TestMachine said the flaw could break that protection. According to the firm, an attacker with direct access to the Ledger device through a connected app could send another command while the first transfer was still under review.

That second command could replace the data used for signing. The device could still show details from the first transfer during the review. In a serious case, a user might see a small token transfer and approve it. The device could instead sign a different action, such as a broad token approval for an attacker.

The reported attack was a race condition in the Ethereum app’s signing flow. In simple terms, two actions could compete for control while the user was still reviewing a transfer.

TestMachine Says Its AI Found the Issue

TestMachine said its Azimuth system found the flaw during a self-run scan. The company said it tested the issue on a Ledger Flex. It also said shared code could affect the Nano X, Nano S Plus, Stax and Apex. Ledger has not published a full notice confirming every affected model.

TestMachine’s work shows how AI is changing safety testing. Its Azimuth system searches for software flaws and tests suspected bugs. Ledger Donjon uses a similar approach. It is Ledger’s internal safety testing team and runs a bug bounty program.

Ledger Says the Patch Came First

Guillemet says Donjon found the bug and sent out a fix before TestMachine went public. He said TestMachine contacted Ledger’s bounty program only after the patch was live. Ledger’s bounty program asks testers to report flaws in private. This gives the company time to check a report and keep users safe before a public release.

TestMachine has given a different account. It says it found and checked the issue, then shared its findings with Ledger. It also said it declined a bounty. Neither side’s full timeline has been proved on its own.

There is another important detail. Ledger’s public Ethereum app changelog currently shows the firm released version 1.22.2 on August 12. Some reports identified version 1.22.2 as the patched app.

The GitHub changelog entry, however, doesn’t specify what issue the version patched. But it does indicate a version 1.22.1 released on May 26, 2026, noting that it fixed security issues. Ledger hasn’t given out enough detail to confirm the fix by version number alone, they only advised updating the apps.

What Ledger Users Should do

Ledger says users should keep firmware and apps up to date. Users should also review every transfer on the Ledger device before approving it.

Ledger’s developer documentation says Clear Signing works with Transaction Check on supported touchscreen devices. Clear Signing shows transfer details, while Transaction Check can warn about risky activity.

Users should not approve a transfer simply because it appears in a familiar app. The device screen remains the final point to review.

There is no confirmed public report of crypto theft linked to this specific flaw as of August 25. The bigger issue is the release dispute. Ledger says its team found and fixed the bug first. TestMachine says its AI system found and checked the same weakness.

What is clear is that the flaw involved a sensitive part of the signing process. Clear signing exists so users can check what they are signing before they approve it.

For Ledger owners, the practical answer does not change: update the device firmware, update the Ethereum app and review transfer details on the device before signing.

Security failures can have far-reaching consequences. In a separate case, 23andMe agreed to a $46.75 million settlement after its 2023 breach exposed genetic data from 6.9 million people, with weak protections against credential stuffing contributing to the incident.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.