Ledger's Ethereum App Vulnerability Patched, Users Still At Risk
A critical vulnerability has been discovered in Ledger's Ethereum app that could have allowed hackers to drain a crypto wallet during a single transaction. The bug, which was found by Ledger's internal security team using AI-powered vulnerability detection tools, had already been patched quietly on August 12 with version 1.22.2.
According to Charles Guillemet, Ledger CTO, the vulnerability would have allowed malicious decentralized applications (DApps) to swap a harmless transfer for an unlimited token approval, granting backdoor access to all ERC-20 tokens on users' Ledger hardware wallets. However, he noted that users who keep their Ledger apps up to date are protected.
The bug was publicly disclosed by TestMachine, an AI-powered security research team, on August 23. Although it had not been exploited as of press time, Ledger users who have not updated to the latest version remain vulnerable. The company has urged all its customers to update to the latest version, particularly noting that the vulnerability may not affect Ledger Nano S users.
This is not the first security issue faced by Ledger in 2026. Earlier this year, the company reported two more severe vulnerabilities, including a bug in their Zilliqa app that exposed private keys through flawed random number generation and led to the theft of 683 million ZIL from over 6,700 accounts.