Key Takeaways
- On August 12, Ledger deployed a security patch for its Ethereum application in version 1.22.2, addressing the issue before making any public announcement
- The vulnerability stemmed from a race condition that potentially allowed malicious software to substitute legitimate transactions with fraudulent ones during the signing process
- Ledger’s specialized security division, Donjon, identified the security weakness using artificial intelligence-powered research methods before external parties reported it
- Between August 21-23, security analyst TestMachine revealed the vulnerability publicly, prompting Ledger’s CTO Charles Guillemet to accuse them of creating unnecessary panic
- As of August 24, 2026, there were no verified incidents of cryptocurrency theft attributed to this security flaw
On August 12, 2026, Ledger implemented a critical security update for its Ethereum hardware wallet application. The patch arrived through Ethereum app version 1.22.2, yet the company maintained near-complete silence about the fix until external pressure forced transparency.
The security weakness centered on a race condition vulnerability within APDU command processing. APDU, or Application Protocol Data Unit, serves as the fundamental communication protocol linking desktop software with the secure element chip embedded in Ledger hardware wallets.
When users engaged in clear signing operationsāwhere transaction information displays in human-readable format on the device screenāan adversarial command could interfere. This interference created an opportunity to substitute the authentic transaction with a malicious alternative before user authorization completed.
In practical exploitation scenarios, victims might have thought they were confirming a modest token transfer. Instead, they could have unknowingly granted unlimited token permissions to an attacker’s wallet address.
Discovery and Internal Detection
Ledger’s dedicated security research unit, Donjon, uncovered the vulnerability through internal investigation before external security researchers submitted reports. The team leveraged artificial intelligence-enhanced analysis tools to locate and remediate the security gap.
The company rolled out the security update without accompanying public notification. For approximately ten days following deployment, no security bulletin, corporate blog entry, or official communication addressed the fix.
This silence ended when TestMachine, an independent security researcher, publicly documented the vulnerability between August 21 and 23. TestMachine detailed the mechanics of the race condition and confirmed successful validation of the exploit on a Ledger Flex hardware wallet.
According to TestMachine’s disclosure, shared codebase architecture suggested the vulnerability potentially affected additional device models, including Nano X, Nano S Plus, Stax, and Apex units. The researcher stated they communicated their findings to Ledger but refused the company’s bug bounty compensation.
Conflicting Narratives Between Ledger and TestMachine
Charles Guillemet, serving as Ledger’s Chief Technology Officer, stated that TestMachine only initiated contact with the company’s bug bounty program after version 1.22.2 had already been released. He asserted the researchers failed to coordinate with Ledger’s security team before publishing statements that suggested the vulnerability remained unpatched.
According to Guillemet, the security fix had been actively deployed for approximately fourteen days when TestMachine made their public disclosure. He criticized the researcher’s presentation approach, characterizing it as an effort to manufacture attention through sensationalism.
TestMachine presented an alternative version of events. The researcher claimed independent discovery and verification of the bug, followed by responsible notification to Ledger. They rejected the bounty payment and proceeded with independent publication of their research.
At the time of this reporting, no comprehensive proof-of-concept demonstration showing successful fund extraction across all mentioned device models had been made publicly accessible.
Examination of Ledger’s public Ethereum application code repository reveals multiple security-focused modifications implemented throughout August, addressing signing state management and message finalization procedures. However, repository documentation doesn’t explicitly identify which specific commit addresses the disclosed vulnerability.
Users of Ledger hardware wallets should immediately verify their device firmware and Ethereum application have been upgraded to version 1.22.2 or more recent releases. Simply updating Ledger Live software on computers or mobile devices will not automatically update applications stored on the hardware wallet itself.
As of August 24, 2026, Ledger had not established any victim compensation program or issued emergency response protocols specifically related to this security incident.





