Key Takeaways
- A critical security flaw in Ledger’s Ethereum application was resolved on August 12 with version 1.22.2 released without public announcement
- The vulnerability was a race condition exploit allowing malicious applications to substitute legitimate transactions with fraudulent ones during the signing process
- The flaw was identified by Ledger’s own Donjon security team utilizing AI-powered research tools before external discovery
- A security expert known as TestMachine revealed the vulnerability publicly around August 21-23, prompting Ledger CTO Charles Guillemet to criticize the disclosure as attention-seeking
- As of August 24, 2026, no verified instances of cryptocurrency theft related to this security flaw had been documented
On August 12, 2026, Ledger quietly deployed a security patch for a critical vulnerability affecting its Ethereum hardware wallet application. The update, released as Ethereum app version 1.22.2, contained a fix for a serious security issue that remained undisclosed to the public for nearly two weeks.
The security issue centered around a race condition vulnerability within APDU command processing. APDU, or Application Protocol Data Unit, represents the communication protocol that facilitates interaction between computer software and the secure element embedded within Ledger hardware wallets.
The vulnerability specifically affected clear signing operations, where users view human-readable transaction information on their device screen. A malicious command executed concurrently could intercept and substitute the original transaction with an unauthorized one before user approval was finalized.
In a practical attack scenario, victims could have inadvertently approved malicious transactions while believing they were authorizing benign operations. For instance, what appeared to be a minor token transfer could actually have granted unlimited token approval to an attacker’s wallet address.
Discovery and Internal Resolution
Ledger’s proprietary security research division, Donjon, uncovered the vulnerability through internal auditing processes before any external security researcher reported it. The team leveraged artificial intelligence-enhanced security analysis tools to detect and remediate the issue.
The security patch was implemented silently without accompanying public communication. For approximately ten days following the fix deployment, no security bulletin, corporate blog post, or official notification was issued to inform users.
The situation changed dramatically when security researcher TestMachine independently discovered and publicly revealed the vulnerability between August 21 and 23. TestMachine provided technical details explaining the race condition mechanism and confirmed successful validation on a Ledger Flex hardware device.
According to TestMachine, shared codebase architecture suggested the vulnerability potentially affected multiple Ledger products, including Nano X, Nano S Plus, Stax, and Apex models. The researcher claimed to have notified Ledger of their findings but rejected the company’s bug bounty compensation offer.
Conflicting Accounts Between Ledger and Researcher
Charles Guillemet, Ledger’s Chief Technology Officer, stated that TestMachine only reached out to Ledger’s bug bounty program after the security patch had already been distributed. According to Guillemet, the researchers failed to coordinate with Ledger’s security team before publishing statements that suggested the vulnerability remained unpatched.
Guillemet emphasized that the security fix had been operational for approximately two weeks before TestMachine’s public disclosure. He criticized the disclosure approach, characterizing it as deliberately sensationalized to attract publicity rather than prioritize user security.
TestMachine presented a contrasting narrative, asserting independent discovery and verification of the security flaw followed by appropriate notification to Ledger. The researcher opted to decline financial compensation and proceeded with public disclosure of the findings.
At the time of publication, no comprehensive exploit demonstration showing successful fund extraction across all affected device models had been made publicly available.
Ledger’s open-source Ethereum app code repository displays multiple security-focused commits throughout August, addressing signing state management and message finalization processes. However, repository records don’t explicitly link a specific commit to this particular vulnerability.
Users of Ledger hardware wallets should immediately verify they’re running the latest device firmware along with Ethereum app version 1.22.2 or newer. Simply updating Ledger Live desktop or mobile applications doesn’t automatically update applications installed on the physical hardware device.
As of August 24, 2026, Ledger has not initiated any user compensation program or issued emergency security protocols specifically related to this vulnerability.



