Ledger Fixes Ethereum App Signing Bug Before Public Disclosure
TLDR
Ledger fixed a bug in its Ethereum app’s clear signing feature before security firm TestMachine went public with it
TestMachine says a malicious app could swap transaction data while a user reviewed it on their device screen
Ledger’s Chief Technology Officer Charles Guillemet says the fix shipped about two weeks before the report came out
No confirmed cases of stolen funds tied to this specific flaw have surfaced as of August 24, 2026
Ledger and TestMachine disagree over how and when the issue was disclosed
Ledger says it patched a bug in its Ethereum application before another security firm made the issue public. Chief Technology Officer Charles Guillemet shared the update on August 23.
The bug affected what Ledger calls clear signing. This feature shows transaction details on the device screen so users can check what they are approving.
Guillemet said Ledger’s internal team, called Ledger Donjon, found the bug using an artificial intelligence research tool. He said the fix went out roughly two weeks before his public statement.
What Clear Signing Does
Clear signing lets users see amounts, addresses, and smart contract actions in plain text. This is meant to replace approving a transaction based on an unreadable code string.
Security firm TestMachine says its research tool, called Azimuth, found a way around this safeguard. The firm claims a malicious app could send a second command while a user was still looking at the first transaction.
TestMachine says this involved communication between a connected app and Ledger’s Ethereum app. The firm claims an attacker could replace an expected transaction with a different one before the user finished approving it.
One example described by TestMachine involved swapping a small transaction for a broader token approval. The device would show one action while quietly preparing another.
Ledger confirmed a bug existed in what it called certain clear signing flows. Guillemet did not share a full technical breakdown or list of affected versions.
Disclosure Timeline in Dispute
TestMachine says it tested the flaw on a Ledger Flex device. The firm also said shared code could make other models relevant, including the Nano X, Nano S Plus, Stax, and Apex.
These claims come from TestMachine’s own account of its research. A full public demonstration of stolen funds across every named device was not available at the time of publication.
Guillemet pushed back on how the disclosure was handled. He said TestMachine reached out to Ledger’s bounty program only after the fix had already shipped.
He also said the researchers did not confirm with Ledger’s bounty team before making claims that suggested the issue was still active. He described this as manufacturing fear for attention.
TestMachine said it shared and verified the finding with Ledger but turned down a bounty payment. The two sides have not reached agreement on the sequence of events.
Ledger’s public code repository shows several security changes made in August. These touch on signing states and message handling, though it is not clear which change matches the disclosed bug.
What Users Should Do Now
Ledger recommends updating the Ledger Wallet software, device firmware, and the Ethereum app itself. Updating only the desktop or mobile app may not be enough if the device app is outdated.
Users should also check transaction details directly on their device screen before approving anything. Ledger warns that blind signing remains risky since not every smart contract action can be shown in readable form.
This case differs from an earlier Zilliqa signing flaw that exposed private keys. That issue affected Zilliqa’s own Ledger app and could not be fixed for keys already exposed through past signatures.
As of August 24, Ledger has not announced any compensation plan or fund recovery process tied to this bug. The company has also not issued a formal advisory naming exact affected versions.
