Key Takeaways
- On August 12, Ledger deployed a security update for its Ethereum application, releasing version 1.22.2 with no prior public announcement
- The vulnerability involved a race condition exploit that could enable malicious applications to substitute legitimate transactions with fraudulent ones during the signing process
- Ledger’s Donjon security division identified the security weakness using artificial intelligence-enhanced research methodologies before external reports emerged
- Independent security analyst TestMachine revealed the vulnerability publicly during August 21-23, prompting Ledger CTO Charles Guillemet to criticize the disclosure as “manufacturing fear for attention”
- As of August 24, 2026, there were no verified instances of cryptocurrency theft attributed to this security weakness
On August 12, 2026, Ledger deployed a critical security update for its Ethereum hardware wallet application. The remediation arrived in Ethereum app version 1.22.2. The company maintained near-complete silence about the fix until an independent security researcher brought the matter to public attention.
There’s some FUD circulating about Ledger signers, pushed by a “smart contract security” company claiming a vulnerability in the Ledger Ethereum app.
There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability…
— Charles Guillemet (@P3b7_) August 23, 2026
The security weakness stemmed from a race condition within APDU command processing. APDU, or Application Protocol Data Unit, represents the communication protocol that facilitates interaction between computer software and the secure element chip embedded within Ledger hardware wallets.
The vulnerability emerged during clear signing operations, where the device displays human-readable transaction information on its screen. A malicious command executed concurrently could intercept and substitute the original transaction with an alternative one before user confirmation completed.
In practical attack scenarios, users might have approved what appeared to be a minor token transfer. However, the actual authorization could have granted unlimited token spending permissions to an attacker-controlled wallet address.
Discovery and Internal Resolution
Ledger’s proprietary security division, Donjon, identified the security flaw before external researchers reported it. The team leveraged artificial intelligence-powered research platforms to detect and remediate the vulnerability.
The security update rolled out without accompanying public communication. For approximately ten days following the patch deployment, no security bulletin, corporate blog entry, or official statement addressed the fix.
This silence ended when security researcher TestMachine made the vulnerability public between August 21 and 23. TestMachine detailed the race condition mechanics and confirmed successful exploitation on a Ledger Flex hardware wallet.
TestMachine additionally indicated that shared codebase elements could extend the vulnerability’s reach to other hardware models, potentially affecting Nano X, Nano S Plus, Stax, and Apex devices. The researcher confirmed sharing findings with Ledger while refusing the company’s bug bounty compensation.
Conflicting Accounts Between Ledger and Researcher
Charles Guillemet, Ledger’s Chief Technology Officer, stated that TestMachine approached Ledger’s bug bounty program only after the security patch had already been deployed. He claimed the researchers avoided engagement with Ledger’s bounty team before publishing assertions that suggested the vulnerability remained unaddressed.
According to Guillemet, the patch had been operational for approximately fourteen days before TestMachine’s public disclosure. He challenged the disclosure’s presentation, characterizing it as a strategy to attract publicity.
TestMachine’s narrative presents a different perspective. The security firm asserted it independently uncovered and verified the vulnerability before informing Ledger. It rejected bounty compensation and opted for public disclosure of its research.
At the time of reporting, no comprehensive proof-of-concept demonstrating successful fund extraction across all identified device models had been made publicly accessible.
Ledger’s open-source Ethereum application repository displays multiple security-focused modifications implemented throughout August, addressing signing state management and message finalization processes. The commit history does not explicitly isolate a single change corresponding to the disclosed vulnerability.
Users operating Ledger devices should immediately update both device firmware and the Ethereum application to version 1.22.2 or subsequent releases. Simply updating desktop or mobile companion software will not replace outdated applications executing on the hardware wallet itself.
As of August 24, 2026, Ledger has not disclosed any user compensation framework or emergency response procedures connected to this security incident.


