Ledger fixed a vulnerability affecting certain clear signing flows in its Ethereum application before another security company disclosed the issue publicly, Chief Technology Officer Charles Guillemet said on Aug. 23.

Guillemet said Ledger Donjon, the company’s internal security research team, discovered the bug using an artificial intelligence vulnerability research system. Ledger deployed the fix approximately two weeks before his statement, according to his post.

Users with current Ledger firmware and applications are protected, Guillemet said. No independently verified reports of funds stolen through this specific vulnerability had emerged by Aug. 24.

There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.

There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability…

— Charles Guillemet (@P3b7_) August 23, 2026

Ledger Ethereum app bug affected clear signing

Clear signing is intended to show transaction details in a readable format on a Ledger device before the user approves them. It allows users to check amounts, addresses and smart contract actions instead of authorizing an unreadable transaction hash.

TestMachine, the security company behind the Azimuth artificial intelligence research tool, said the vulnerability could undermine this review process. According to the company’s public thread, a malicious application could allegedly send a competing command while a user was still reviewing the original transaction.

The reported issue involved Application Protocol Data Unit communication between the connected application and Ledger’s Ethereum app. TestMachine claimed this could let an attacker replace an expected transaction with another action before the user completed approval.

Under that scenario, a device could display one transaction while preparing another for signing. One possible result described by researchers involved replacing a limited transaction with a broader token approval.

Ledger acknowledged that a bug existed in “certain clear signing flows.” However, Guillemet did not publish a detailed technical description, affected version list or security advisory explaining the full attack requirements.

Ledger and TestMachine dispute the disclosure timeline

TestMachine said its Azimuth system found the issue during an autonomous scan and validated it on a Ledger Flex. The company also claimed that shared code made other models potentially relevant, including Nano X, Nano S Plus, Stax and Apex devices.

Found by Azimuth during an autonomous scan of the Ledger Ethereum app. Validated on Flex. Shared and verified with the team. Declining any bounty. Same shared APDU/UI code across Nano X, Nano S Plus, Stax, Apex.

The power of always on securityhttps://t.co/fH5mO97Kkp

— TestMachine (@testmachine_ai) August 22, 2026

Those statements remain the company’s account of its research. A complete public proof of concept demonstrating fund theft across every named device was not available at publication time.

Guillemet disputed how the disclosure was presented. He said TestMachine contacted Ledger’s bounty program after the company had already shipped its fix. He further alleged that the researchers did not discuss the issue with Ledger’s bounty team before publishing claims that suggested it remained unresolved.

“It was fixed and deployed two weeks ago,” Guillemet said. He described claims that the problem remained active as “manufacturing fear for attention.” TestMachine, by contrast, said it shared and verified the finding with Ledger but declined a bounty.

Ledger’s public Ethereum application repository shows several security-related changes during August. These include fixes involving signing states, application context handling and message finalization. The available records do not clearly identify which change corresponds to the disclosed clear signing issue or confirm the precise deployment date across Ledger’s device application store.

Users should update firmware and the Ethereum app

Ledger users should update the Ledger Wallet software, device firmware and installed Ethereum application. Updating only the desktop or mobile interface may not replace an outdated application running on the hardware device.

Users should also verify transaction details directly on the secure device screen. Ledger’s guide warns that blind signing remains risky because the device cannot present every smart contract action in a readable format.

As previously reported, Ethereum introduced human readable transaction summaries through the ERC-7730 standard. Ledger helped develop the system before stewardship moved to the Ethereum Foundation.

The latest incident differs from the previously reported Zilliqa signing flaw that exposed private keys. Zilliqa said that vulnerability affected its own native Ledger application and could not be corrected for keys already exposed through recorded signatures.

Ledger has not announced any compensation process, emergency transaction suspension or asset migration related to the Ethereum app issue. Further confirmation would require a technical advisory naming the affected versions, patched release and precise conditions needed to exploit the flaw.