Ledger hardware wallets have received an update that fixes a dangerous error in the logic of transparent transaction signing in the Ethereum app. The company's CTO, Charles Guillemet, confirmed that the bug was discovered and neutralized by the internal security division Donjon, which used AI tools to search for vulnerabilities. The patch is already included in app version 1.22.2.
The essence of the problem
The vulnerability lay in the handling of APDU commands—service messages used to interact with the device. In certain scenarios, a malicious smart contract could substitute transaction data at the moment of signing. This opened the door to an attack where a user, confident they were confirming a small transfer, actually approved unlimited access to their funds for an attacker's address. In essence, this is a classic manipulation of signature "transparency," where the device shows one amount while a completely different instruction goes out to the network.
Guillemet emphasizes that device owners who have installed the latest firmware and app versions are fully protected. However, the incident also exposed another, equally important issue—the ethics of information disclosure.
Conflict over responsible disclosure
According to the executive, an external "smart" security company that first reported the vulnerability acted improperly. It sought a bounty only after the fix had already been released, without first contacting the Ledger team. Instead, a public thread followed, creating the false impression that the issue remained unresolved. A user under the pseudonym TestMachine detailed the potential mechanics of transaction substitution, which only heightened the panic. Guillemet directly called this a "violation of the principles of responsible vulnerability disclosure."
This case is yet another reminder that even the most reliable hardware wallets are not immune to complex attack vectors. But what is more telling here is the behavior of researchers: the race for hype and bounties should not undermine trust in the security of the entire ecosystem. Notably, the incident occurred against the backdrop of a data breach at Ledger's competitor, Trezor, where nearly 14,000 customers were affected due to a hack of the logistics partner ShipMonk. Cybersecurity issues in the industry are becoming increasingly acute, and manufacturers have to balance between protecting code and protecting reputation.