Ledger Fixes Critical Vulnerability in Ethereum App
Hardware wallet provider Ledger has patched a critical vulnerability in its Ethereum app that could have allowed malicious decentralized apps to swap legitimate transactions for harmful ones during signing.
The bug, which involved an APDU command timing issue, was quietly fixed in version 1.22.2 of the Ethereum app on August 12, 2026, before a security researcher publicly disclosed the issue days later.
According to Ledger, the flaw could have allowed users to unknowingly approve unlimited token transfers to attackers, potentially resulting in significant financial losses.
Fortunately, no reported losses from the vulnerability have been made public so far, and users are advised to update their Ethereum app to stay protected.