Morning Edition · Tuesday, August 25, 2026Published at 1:50 AM EDT · New York
The fix shipped on 12 August in app version 1.22.2, and Ledger and the researchers who published the finding disagree publicly over who found it and how serious it was.

Ledger fixed a defect in the Ethereum application on its hardware wallets that could allow a malicious website to substitute transaction data while a user was reviewing a payment on the device screen. CryptoSlate reports that version 1.22.2 adds two signing-state safeguards, rejecting signature commands that arrive while a review is still open and fixing the signing mode at the start of an operation. The reported attack path is a race between commands sent to the device over a browser connection, which is why the flaw affected the clear-signing flow, the feature marketed precisely to stop users approving contents they cannot read.
The two sides tell different stories about discovery. Ledger's chief technology officer, Charles Guillemet, said the company's internal Donjon security team found the bug with an artificial-intelligence vulnerability research system and shipped the fix before the public warning, and he characterized the disclosure as manufacturing fear for attention. The researchers operating as TestMachine say their own automated system found the issue and that they shared and verified it with Ledger. No reports of lost funds have surfaced. CryptoSlate notes that public physical validation of the substitution path is limited to one device model, the Ledger Flex, so the real-world reach across the product line is documented less thoroughly than the patch is.
Both accounts point to the same underlying condition. Automated code analysis is now finding implementation faults in signing firmware faster than the disclosure norms of the industry can absorb them, and the argument moves to timing and credit rather than to whether the defect was real.
The engineering response elsewhere is to remove the attack surface rather than try to manage it after the fact. Blockstream shipped desktop version 3.5.0 of its application with fully air-gapped signing for its Jade device over scanned codes, alongside Lightning payments in beta. A signer with no live data connection to the host computer cannot lose a race with commands sent by that computer.
Part of a tracked trend
Implementation Bugs, Not Just Exploits, Threaten Custody
Cryptographic implementation errors in wallets and signers (biased nonces, reused randomness, faulty derivation) keep surfacing as a distinct custody risk alongside smart-contract exploits, eroding the assumption that certified hardware protects keys.
Start a discussion in Townsquare.
More from this edition
Regulated custodians and exchange-traded products gain when self-custody firmware looks uncertain, TestMachine gains visibility for its automated vulnerability tool, and Ledger gains from the account in which the fix preceded the warning.
Both sides agree the defect was real and patched on 12 August in version 1.22.2, so the contested part is credit and timing rather than existence, and public physical validation is limited to one device model with no confirmed losses, which leaves the practical reach of the flaw undetermined.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The value of a hardware wallet rests on one claim, that the screen shows what the key signs. Each implementation defect in that path transfers demand from self-custody to custodians and exchange-traded products, because holders who cannot audit firmware react to uncertainty by outsourcing it. The commercial winners are regulated custodians and issuers, and the losers are device makers whose premium depends on a trust story that automated code review keeps testing.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CryptoSlate · Blockstream Blog
Comments
0No comments yet.