Ledger Ethereum App Quietly Patched for Serious Vulnerability
On August 12, 2026, Ledger quietly patched a serious flaw in its Ethereum app without publicly acknowledging it. The vulnerability was a race condition that could have allowed a malicious application to swap a legitimate transaction for a harmful one while the user was still approving it on their device screen.
The bug centered on APDU commands, which are used by Ledger devices to communicate between the connected computer and the secure chip that signs transactions. This vulnerability undermined Ledger's core security promise of clear signing, where users can see exactly what they're approving before confirming it.
Donjon, Ledger's internal security unit, claimed to have discovered the vulnerability on its own using AI-assisted research tools before any external researcher flagged it. However, TestMachine, an AI security firm, published its findings between August 21 and 23, 2026, using its autonomous AI agent Azimuth.
Ledger CTO Charles Guillemet pushed back against how the disclosure was framed, stating that TestMachine only contacted Ledger's bounty program after the fix had already shipped. He accused TestMachine of manufacturing fear for attention rather than practicing responsible security research.