Crypto news

24.08.2026
08:22

Ledger has closed a critical vulnerability in its Ethereum application: what users need to know

hack

Ledger hardware wallets have received an update that closes a potentially dangerous vulnerability in the application for working with Ethereum. The company's CTO, Charles Guillemet, confirmed that the bug affected specific transparent transaction signing scenarios, and the fix has already been distributed in version 1.22.2.

The issue was discovered by the internal Donjon team—Ledger's specialized cybersecurity unit, which used its own set of AI tools to search for vulnerabilities. According to Guillemet, users who have installed the latest firmware and application patches are fully protected.

Threat mechanics and potential risks

The vulnerability lay in the handling of APDU commands (Application Protocol Data Unit message format) in the Ethereum application. Under certain conditions, a malicious smart contract could theoretically substitute transaction data at the moment of signing. In practice, this meant that a user, confident in confirming a small transfer, could unknowingly grant unlimited access to their funds to an attacker's address.

What raises particular concern is not the fact of the bug's discovery itself, but how external researchers presented this story. Guillemet criticized the public disclosure of the issue: according to him, a third-party company positioning itself as smart contract security experts sought a reward only after the fix's release. Moreover, it did not interact with the Bug Bounty program team, and then published a thread creating a false impression of an unresolved problem.

In particular, an X user under the pseudonym TestMachine described in detail the potential mechanics of transaction substitution, which only amplified the wave of FUD. Guillemet called such actions "a violation of the principles of responsible vulnerability disclosure."

Context and my assessment

The incident occurred against the backdrop of a recent data leak at a competitor—Trezor, where on August 13, nearly 14,000 customers were affected due to a breach of the logistics partner ShipMonk. This serves as a reminder that even the most reliable hardware solutions are not immune to attacks on adjacent links.

In my view, Ledger's response here is telling: the company did not hush up the problem but promptly released a patch and openly explained the situation. However, the very existence of such vulnerabilities in transparent signing mechanisms underscores that a hardware wallet is a reliable but not absolute barrier. Users should regularly update firmware and critically evaluate any reports of "critical bugs," especially if they come from anonymous sources without coordination with the manufacturer.