Ledger’s in-house research team says it found the bug first and fixed it first, but the company published no security bulletin describing what it had closed.
Ledger CTO Charles Guillemet said on August 23 that a “smart contract security” company circulated fear about a vulnerability in the Ledger Ethereum app that had already been patched two weeks earlier, in a post on X that had drawn 49,900 views by 11:26 PM IST.
What Ledger’s Own Records Show
The public changelog for LedgerHQ’s app-ethereum repository lists version 1.22.2 with the release date 2026-08-12. Its entire “Fixed” section reads: “Security issues.”
The version immediately before it, 1.22.1, dated 2026-05-27, lists one fix: “Instability in APDU communication handling.” APDU is the Application Protocol Data Unit, the command channel between a host application and the signing device.
Ledger Donjon, the company’s internal security research team, maintains a public security bulletin index. The most recent entry is LSB 022, dated 4 June 2026, covering Monero secret key recovery through Keccak state exposure. No bulletin on that index covers the August 12 release.
What Guillemet Said
In his post, Guillemet said the bug concerned certain clear signing flows, that Donjon found it using the team’s AI-powered vulnerability research suite, and that the fix was deployed two weeks earlier. He said users who keep their Ledger apps updated are protected.
On the disclosure sequence, Guillemet said the company that published the finding contacted Ledger’s bounty program only after the fix had already shipped and never discussed the issue with the bounty team. He said the firm then published a thread implying the problem was unresolved.
“…Then they published a thread implying the problem is unsolved. It is not. That’s not security research. That’s manufacturing fear for attention,” Guillemet wrote.
He added that AI-speed research only improves ecosystem safety if researchers still disclose responsibly and verify before publishing, and said an actor skipping those steps is net negative regardless of tooling.
What the Disclosing Firm Claims
TestMachine, which operates an AI agent called Azimuth, said it found the bug during an autonomous scan of the Ledger Ethereum app and validated it on a Ledger Flex. According to the same report, TestMachine states Azimuth catches 86.3% of known bugs with roughly 2.7% false positives on the firm’s own EVMBench benchmark.
TestMachine’s described mechanism is that a malicious website could send the device a second command over the APDU channel while a user was still reviewing the first, so the transaction displayed and the transaction signed could differ.
The firm said it declined a bounty and cited shared APDU and UI code across Nano X, Nano S Plus, Stax, and Apex.
The Precedent in Ledger’s Own Archive
Donjon’s bulletin index contains a directly comparable case. LSB 015, dated 13 January 2021, is titled “TX data of unsupported crypto assets are not displayed by the Ethereum app 1.6.0” — a disclosure about the same application failing to show users what they were signing. That issue received a numbered, dated, publicly documented bulletin.
What Owners Can Check
Ledger users can open Ledger Live, update the Ethereum app, and confirm the installed version reads 1.22.2. Guillemet’s stated position is that updated apps are protected.
The dispute arrives after a run of Ledger-adjacent security stories this year, including Zilliqa’s disclosure of a five-year private key vulnerability in its Ledger app, Ledger’s TRNG explanation following the Coldcard theft, and ZachXBT’s criticism of hardware wallets.
