Ledger's Ethereum App Bug Exposed: AI Speed vs Human Coordination
A security firm called TestMachine exposed a bug in Ledger's Ethereum app that allowed malicious websites to trick users into signing unlimited token approvals. The flaw was discovered using an AI agent called Azimuth, which found it during an autonomous scan of the app.
The bug worked by sending a second command while the user was still reviewing the first one, allowing the device to accept the swap and sign an approval without the user's knowledge or consent. This type of phishing has been responsible for around $1 billion in crypto stolen since May 2021.
Ledger's CTO, Charles Guillemet, called the disclosure 'fear-mongering' and claimed that Ledger had already fixed the bug two weeks earlier, with a quiet fix released on August 12. He argued that TestMachine contacted the bounty program only after the patch shipped and never spoke with the team.
The discovery highlights the ongoing debate about AI's role in security research. Both sides used machine learning to reach the same defect, and Ledger has made the argument before that AI attackers threaten wallets more than weak hardware does. Guillemet drew his line at discipline, emphasizing the importance of responsible disclosure and verification.