Ledger has patched a vulnerability in its Ethereum application that could let a malicious app swap a user’s transaction during signing, making the hardware wallet approve a different action than the one shown on its screen. The company’s internal security team, Ledger Donjon, said it found and fixed the bug with an AI-powered research system and shipped the update in mid-August, roughly two weeks before an outside firm disclosed the issue publicly. The flaw sat inside clear signing, the safety feature Ledger built so people can read what they are approving. Clear signing is a method that displays a transaction’s amounts, addresses, and contract actions in plain language on the device screen so the user can verify them before approving. No thefts tied to the bug have been confirmed.
Key takeaways
- Ledger fixed an Ethereum app bug that could substitute a transaction while a user reviewed it on the device screen.
- The patch shipped around mid-August 2026. CTO Charles Guillemet said Ledger Donjon found it with an AI vulnerability research tool.
- Security firm TestMachine, using its Azimuth AI scanner, disclosed the flaw publicly between Aug 21 and 23, setting off a dispute over the timeline.
- No confirmed thefts. Ledger urges owners to update device firmware and the Ethereum app to the latest version.
Published: August 26, 2026, 09:20 UTC
How the transaction swap worked
The bug was a race condition in the way the Ethereum app talked to connected wallet software. A race condition is a flaw where the timing of two competing commands changes the result in a way the system never intended. Ledger’s app trades data with desktop and browser software through APDU messages, the low-level commands that move instructions between a computer and the wallet’s secure chip.
According to TestMachine, a malicious decentralized app with a browser connection to the device could fire a second APDU command while the user was still reviewing the first transaction. The screen would keep showing the original details while the wallet prepared a different action to sign. Researchers described one outcome where a small, capped transfer was replaced with a broad token approval, the kind of standing permission that can empty a wallet in a later transaction. TestMachine said it validated the attack on a Ledger Flex and warned that shared code across the Nano X, Nano S Plus, Stax, and Apex models could leave them exposed too.
Ledger and the researcher dispute the timeline
Both sides agree a bug existed. They disagree on almost everything about how it reached the public. Guillemet said on Aug 23 that Donjon discovered the issue internally, shipped the fix about two weeks earlier, and that TestMachine contacted Ledger’s bug bounty program only after the patch was already live. He called claims that the flaw remained active “manufacturing fear for attention” and described the public thread as FUD.
TestMachine gave a different account. It said its Azimuth system found the bug during an autonomous scan, that it shared and verified the finding with Ledger, and that it declined a bounty. Neither version has been independently confirmed. Ledger has not released a formal security advisory naming the affected app versions or the exact deployment date, and its public code repository shows several August security changes without labeling which one closed this specific hole.
What Ledger owners should do now
Owners should update three things, not one: the Ledger Live or Ledger Wallet software, the device firmware, and the installed Ethereum app. Updating only the desktop or mobile interface can leave an outdated app running on the hardware itself, where the vulnerable code lived. Ledger also repeated its standing advice to check every transaction on the device screen and to avoid blind signing, where a wallet approves a transaction hash it cannot render in readable form.
The disclosure fight arrives during a rough stretch for onchain security. Recent weeks brought a governance attack that drained Term Finance and a multi-bug exploit at Maya Protocol, both of which cost users real money. The Ledger case is different because the patch landed before any confirmed loss, but it sharpens a question the industry keeps asking: how should security teams and outside researchers coordinate when AI tools are now finding bugs on both sides of the fence.
Frequently asked questions
Were any funds stolen through the Ledger Ethereum app bug?
No confirmed thefts had surfaced as of Aug 24, 2026. Ledger says it patched the vulnerability before public disclosure, and no independently verified reports of stolen funds tied to this specific flaw have emerged.
What is clear signing on a Ledger device?
Clear signing shows a transaction’s amounts, addresses, and contract actions in readable text on the wallet screen. It lets users confirm what they are approving instead of signing an unreadable hash, a practice known as blind signing.
How do I protect my Ledger from this issue?
Update the Ledger software, the device firmware, and the Ethereum app to the latest versions. Updating only the phone or desktop app is not enough, because the vulnerable code runs on the hardware device itself.
Sources: crypto.news, Charles Guillemet on X, TestMachine on X, Ledger Academy, Ledger app-ethereum repository.








