---
title: "Ledger Confirms Ethereum App Signing Flaw Already Patched"
date: 2026-08-24
author: "Kelvin Scott"
featured_image: "https://coinlaw.io/wp-content/uploads/2026/08/ledger-ethereum-signing-flaw-patched.jpg"
categories:
  - name: "Cryptocurrency"
    url: "/crypto.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Ledger Confirms Ethereum App Signing Flaw Already Patched

Ledger CTO Charles Guillemet said on August 23, 2026, that the company had already fixed a clear-signing flaw in its Ethereum app before security firm TestMachine disclosed it publicly. No independently verified reports of funds stolen through this specific vulnerability had emerged by Aug. 24.

## What to Know?

- The fix “was deployed two weeks ago”, according to Guillemet, before TestMachine went public with the vulnerability.
- Azimuth, TestMachine’s AI vulnerability scanner, found the issue during an autonomous scan and validated it on a Ledger Flex device, per TestMachine.
- Ledger’s own public release feed shows the newest tagged Ethereum app release is version 1.22.1, dated May 27, 2026, with nothing tagged in August.
- Ledger has not published a detailed technical advisory, affected version list or security advisory naming the full attack requirements.
- Claims that the bug remains unresolved amount to “manufacturing fear for attention,” per Guillemet.

## Ledger and TestMachine Dispute the Timeline

Clear signing shows a Ledger device owner the actual amounts, addresses and smart contract actions on the device screen before they approve a transaction. TestMachine said a malicious application could send a competing command while a user was still reviewing the original transaction.

> There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.  
>   
> There was a bug concerning certain clear signing flows. It was found by the [@DonjonLedger](https://x.com/DonjonLedger?ref_src=twsrc%5Etfw) using their AI-powered vulnerability…
> 
> — Charles Guillemet (@P3b7\_) [August 23, 2026](https://x.com/P3b7_/status/2091585430030344262?ref_src=twsrc%5Etfw)

 Under that scenario, the screen could show one transaction while a different one was prepared for signing. One possible result described by researchers involved replacing a limited transaction with a broader token approval.

TestMachine said shared code made other models potentially relevant, including **Nano X**, **Nano S Plus**, **Stax** and **Apex** devices, beyond the Flex it tested. A complete public proof of concept demonstrating fund theft across every named device was not available at publication time.

Guillemet disputed the disclosure sequence. He said TestMachine contacted Ledger’s bounty program after the company had already shipped its fix, and that the researchers did not discuss the issue with Ledger’s bounty team before publishing.

TestMachine countered that it shared and verified the finding with Ledger but declined a bounty. Neither account is independently confirmed. Guillemet said **Ledger Donjon**, the company’s internal security research team, discovered the bug using an artificial intelligence vulnerability research system, while TestMachine said its Azimuth system found the issue during an autonomous scan. Both accounts credit an AI research system for the find, which compresses the window a vendor has to confirm a fix before an outside researcher goes public.

## The Release Feed Doesn’t Show a Dated Patch

CoinLaw checked Ledger’s Ethereum app source repository against the **“two weeks ago”** claim. As of **Aug. 24**, the most recent tagged release on the public feed is version 1.22.1, published May 27, 2026, whose sole listed change reads: “**Instability in APDU communication handling**“.

No tagged release published in August 2026 appears on the feed, and no release note on it names the clear-signing substitution issue TestMachine described.

That gap does not prove the patch does not exist. [Ledger](https://coinlaw.io/ledger-statistics/) can push app updates through its device app store without cutting a tagged GitHub release, so a fix delivered to end users would not necessarily appear in this repository at all. It does mean a Ledger user cannot use Ledger’s own public source history to confirm the “**two weeks ago**” timeline or identify which app version closed the hole.

| What Ledger has said? | What is publicly verifiable? |
|---|---|
| **Fix “deployed two weeks ago”** | **No August 2026 tagged release on the public feed** |
| **Affected app: Ethereum clear-signing flow** | **No affected-version list published** |
| **Update Ledger Live, firmware, and the Ethereum app** | **No patched-release identifier named** |

Both Guillemet’s statement and Ledger’s own guidance tell users to update, but Ledger did not publish an affected version list or patched release identifier alongside that instruction. A user checking their device has no version number to check against.

The patched version of the [Ethereum app](https://coinlaw.io/ethereum-statistics/) is described as available through the official Ledger Live interface, but updating only that software does not finish the job. Updating only the desktop or mobile interface may not replace an outdated application running on the hardware device itself, so a holder needs to separately open the device’s own app store and reinstall the Ethereum application.

Verifying transaction details on the device screen itself, not the paired app, is the exact control this incident tests, a distinction that browser-extension wallets face too.

Transaction approval manipulation is a recurring category in [Cryptocurrency Fraud](https://coinlaw.io/cryptocurrency-security-fraud-statistics/), which tracks losses tied to compromised signing flows across hardware and software wallets alike.

## CoinLaw’s Takeaway

**Ledger** and **TestMachine** are each asking users to trust an account neither has fully documented. Ledger’s version rests on an internal timeline it has not published evidence for beyond Guillemet’s statement. TestMachine’s version rests on a proof of concept it has not made public.

Neither is a substitute for a dated, versioned security advisory naming what changed and when.

The technical target here matters. Clear signing exists so a Ledger owner does not have to trust the connected software; they can trust their own eyes on the device screen. A substitution bug in that flow attacks the one guarantee a hardware wallet is built to provide.

This does not confirm funds were lost, and it does not confirm the fix hasn’t shipped. It confirms a user cannot yet check their own device against a published version number, and closing that gap is on Ledger.

Definition of Smart Contract. Link to full glossary entry follows the description.**Smart Contract**A smart contract is a self-executing program stored on a [blockchain](https://coinlaw.io/glossary/blockchain/) that automatically enforces agreement terms when predefined conditions are met, without intermediaries.

[Read more](https://coinlaw.io/glossary/smart-contract/)

Definition of Cold Wallet. Link to full glossary entry follows the description.**Cold Wallet**A cold wallet is an offline crypto storage method that keeps private keys disconnected from the internet, reducing the risk of hacking and unauthorized access.

[Read more](https://coinlaw.io/glossary/cold-wallet/)