Home » Ledger Says Ethereum Wallet Flaw Was Patched Before Public Security Warning

Ledger Says Ethereum Wallet Flaw Was Patched Before Public Security Warning

by Terron Gold
0 comments

Ledger says a vulnerability affecting certain Ethereum clear-signing transactions had already been fixed nearly two weeks before an outside security firm publicly warned users about the issue, creating a dispute over responsible disclosure and how hardware-wallet vulnerabilities should be communicated.

Ledger CTO Charles Guillemet said the bug was discovered internally by Ledger Donjon, the company’s security research team, using an AI-powered vulnerability research system. Ledger released the fix in Ethereum app version 1.22.2 on August 12, while the outside warning surfaced on August 23. 

No confirmed user losses have been linked to the vulnerability, and Ledger says users running the latest version of its Ethereum app are protected. 

Vulnerability Could Have Changed What Users Actually Signed

The issue involved certain clear-signing flows inside Ledger’s Ethereum application.

Clear signing is designed to show users understandable transaction information on their hardware wallet before they approve a transaction. That protection is important because crypto users frequently interact with complex smart contracts where blindly signing unreadable transaction data can expose funds.

Security company TestMachine, using an AI agent called Azimuth, said it discovered a race-condition vulnerability affecting the communication between a Ledger device and the software sending it transaction information. 

According to TestMachine’s description, a malicious website could potentially send another command to the device while the user was still reviewing the first one.

That could create a dangerous situation where:

  • The Ledger displays one transaction for the user to review
  • A second command arrives before the first signing process finishes
  • The transaction ultimately signed could differ from what the user believed they approved
  • The attack could occur during certain Ethereum clear-signing workflows 

The vulnerability therefore targeted one of hardware wallets’ most important defenses — making sure the information shown on the device matches what is actually being authorized.

Ledger Says It Found the Bug First

Ledger disputes the implication that TestMachine independently discovered an unresolved vulnerability.

Guillemet said Ledger Donjon had already identified the flaw internally, developed a fix and pushed the corrected Ethereum application to users before TestMachine contacted Ledger’s bounty program. 

Ledger’s public GitHub changelog confirms that Ethereum app version 1.22.2 was released August 12.

However, the changelog contains only a brief description under its fixed section:

“Security issues.”

It does not explain the nature of the vulnerability, its severity or which transaction flows were affected.

That lack of detail ultimately became part of the dispute.

TestMachine Says Its AI Agent Found the Vulnerability

TestMachine says its autonomous security system Azimuth identified the issue while analyzing Ledger’s Ethereum application.

The firm says Azimuth is designed to autonomously search smart contracts and other blockchain-related software for security vulnerabilities.

TestMachine claims its internal EVMBench benchmark shows the system detecting approximately 86.3% of known vulnerabilities with a 2.7% false-positive rate, although those figures come from the company’s own testing. 

The company says it then validated the Ledger vulnerability on a physical Ledger Flex device.

TestMachine also suggested the shared software architecture could make the issue relevant to multiple Ledger devices, including:

  • Ledger Nano X
  • Ledger Nano S Plus
  • Ledger Stax
  • Ledger Flex
  • Other devices using the same Ethereum application components 

The company reportedly declined a bug bounty before publicly discussing the vulnerability.

Ledger Accuses Security Firm of Creating Unnecessary Fear

Guillemet strongly criticized how TestMachine disclosed its findings.

According to Ledger, TestMachine contacted the company’s bounty program only after version 1.22.2 had already been released and never discussed the issue with Ledger’s security team before publicly suggesting that users remained vulnerable. 

Guillemet argued that the vulnerability was already resolved and accused the company of presenting the situation in a way that created unnecessary fear among hardware-wallet users.

The dispute highlights an important cybersecurity practice known as coordinated disclosure.

Researchers who discover serious vulnerabilities will typically:

  1. Privately notify the affected company.
  2. Give developers time to investigate and create a patch.
  3. Confirm whether the fix resolves the problem.
  4. Publicly disclose technical details once users have had time to update.

That process is designed to prevent attackers from learning how to exploit a vulnerability before users can protect themselves.

Ledger Quietly Fixed the Problem Without Publishing a Security Bulletin

Although Ledger says it acted quickly, the incident has also raised questions about its own disclosure practices.

Ledger maintains a public security bulletin archive documenting significant vulnerabilities affecting its products.

However, there is currently no dedicated bulletin explaining the August Ethereum app vulnerability. 

The most recent bulletin listed before this incident was published in June and covered an unrelated Monero vulnerability.

That’s notable because Ledger has previously published detailed security advisories when Ethereum app issues affected what users could see before signing.

For example, a 2021 Ledger security bulletin documented an Ethereum application issue where transaction information for unsupported crypto assets wasn’t properly displayed. 

The current vulnerability appears to have been handled differently.

Ledger patched it but initially disclosed little beyond the phrase “Security issues.”

Users Should Update Ethereum App to Version 1.22.2

For Ledger owners, the most important action is straightforward.

Users should open Ledger Live and confirm that their Ethereum application is updated to at least version 1.22.2

According to Guillemet, users running the updated application are protected from the vulnerability.

Users should also keep both Ledger firmware and individual cryptocurrency applications updated, because security fixes can be distributed independently through app releases.

There is currently no evidence that the vulnerability resulted in confirmed theft of user funds. 

You may also like

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?

This website uses cookies to improve your experience. To read more or opt here visit the privacy policy. Accept Read More