Vulnerability Patched in Ledger’s Ethereum App
Ledger recently patched a vulnerability in its Ethereum app's signing flows that could have allowed malicious dApps to swap legitimate transactions for harmful ones. The fix, version 1.22.2 of the Ethereum app, was quietly released on August 12 without public fanfare.
The bug involved an APDU command race condition, where competing instructions can arrive at the device in a sequence that tricks the signing process. In practical terms, a user could have thought they were approving a small token transfer while actually authorizing unlimited token approvals to an attacker-controlled address.
Ledger's internal security team, Donjon, discovered the flaw and used AI-assisted tools to resolve it before any external researcher flagged it. The company pushed back on public disclosure, characterizing it as fear-mongering. Any user running the latest version of the Ethereum app was already protected, according to Ledger CTO Charles Guillemet.
The vulnerability is notable because it affected Ledger's clear signing flows, which are designed to protect users from blind signing risks. The patch was deployed proactively by Donjon before any external notice was filed.