Ledger Pushes Back Against Ethereum App Security Flaw Claims
A recent controversy has emerged regarding Ledger's Ethereum app, which has been found to have a security flaw. The issue was discovered by Ledger's Donjon security team and AI-powered tools before it was publicly disclosed by a 'smart contract security' company called TestMachine.
According to Ledger's CTO Charles Guillemet, the vulnerability was fixed in version 1.22.2 of the Ethereum app on August 12th, but Ledger did not publicly explain the issue when it released the patch.
The controversy arose because the security flaw caused users to sign something different from what they saw on Ledger's screen, which is a serious concern given that the main security advantage of a hardware wallet is that the device itself allows users to verify transactions before approving them.
Guillemet took to X to clarify that TestMachine reached out to Ledger's bounty program after the fix was already shipped and did not follow responsible disclosure. He added, 'That's manufacturing fear for attention.'