Ledger says Ethereum signing flaw was already fixed

1 hour ago 1



Ledger fixed a vulnerability affecting certain clear signing flows in its Ethereum application before another security company disclosed the issue publicly, Chief Technology Officer Charles Guillemet said on Aug. 23. Summary Ledger says its Ethereum app patch fixed vulnerable clear signing flows before public disclosure occurred. TestMachine claims a malicious application could replace transaction data while users reviewed Ledger device screens. Ledger’s chief technology officer Charles Guillemet says updated firmware and applications protect affected users now. No confirmed thefts tied to this specific signing vulnerability had surfaced by August 24, 2026. Ledger’s public repository shows continuing security fixes, but does not identify every deployed patch clearly. Guillemet said Ledger Donjon, the company’s internal security research team, discovered the bug using an artificial intelligence vulnerability research system. Ledger deployed the fix approximately two weeks before his statement, according to his post. Users with current Ledger firmware and applications are protected, Guillemet said. No independently verified reports of funds stolen through this specific vulnerability ...

Read Entire Article