Ledger's Secret Ethereum Flaw Fixed Before Public Disclosure
A secret vulnerability in Ledger's Ethereum app was patched two weeks before it was publicly disclosed. The bug, discovered by Ledger's internal security team Donjon using AI-assisted tools, allowed a malicious app to swap out a legitimate transaction for a harmful one during signing.
The fix was included in version 1.22.2 of the Ethereum app, released on August 12, 2026. However, the company said almost nothing publicly about the issue until security researcher TestMachine forced the disclosure between August 21-23.
Ledger CTO Charles Guillemet called the public disclosure an attempt to 'manufacture fear for attention.' He stated that the fix had been live for two weeks before TestMachine went public and that no confirmed reports of stolen funds linked to this vulnerability had surfaced as of August 24, 2026.