Ledger Patches Vulnerability in Ethereum Application
Ledger, a prominent crypto hardware wallet firm, has addressed a vulnerability in its Ethereum application that could have allowed malicious actors to substitute transaction details and potentially steal funds. The issue was related to a race condition in certain clear-signing processes, where users review human-readable transaction details on the device screen before approving them.
Security researchers highlighted how a malicious decentralized application with appropriate access could send competing commands during the review window, allowing the data held in memory for signing to be replaced without refreshing the on-screen display. This could have led to a user approving what appeared to be a routine small transfer while the device actually signed a different action, such as an unlimited token approval directed to an attacker-controlled address.
Ledger's internal security research group, known as Donjon, identified the problem using artificial-intelligence-assisted tools and prepared a remedy. The company released Ethereum application version 1.22.2 around August 12, 2026, which introduced safeguards against signing-session replacement and mismatched approval callbacks.
Ledger executives responded firmly to public discussion of the issue, with Chief Technology Officer Charles Guillemet stating that the company's own team had already located and addressed the bug affecting certain clear-signing flows roughly two weeks earlier. He characterized circulating claims as fear, uncertainty, and doubt promoted by an outside group, asserting that users running current firmware and applications were protected.