Ledger Denies Vulnerability Delay, Claims Fix Deployed Weeks Ago
A recent vulnerability affecting Ledger's Ethereum app has been largely debunked by the company itself. According to Charles Guillemet, Chief Technology Officer at Ledger, a 'bug concerning certain clear signing flows' was indeed discovered and fixed before being publicly disclosed.
Guillemet stated that Ledger's internal security research team, DonjonLedger, used an AI-powered vulnerability research system to find the issue. The fix was deployed approximately two weeks prior to Guillemet's statement.
The reported bug involved Application Protocol Data Unit communication between the connected application and Ledger's Ethereum app. TestMachine claimed that a malicious application could send a competing command while a user was still reviewing the original transaction, potentially replacing an expected transaction with another action before the user completed approval.