An artificial intelligence security firm went public with a vulnerability in the Ledger Ethereum app, while hardware wallet manufacturer Ledger stated that it had already resolved the flaw two weeks prior.
The security firm, TestMachine, discovered the bug using its AI agent during an autonomous scan of the Ledger Ethereum app and validated it on a Ledger Flex device. According to the firm, the vulnerability allowed a malicious website to send a second command to the device via the Application Protocol Data Unit channel while a user was reviewing the first command. This could cause a user to approve an unintended transaction, such as an unlimited token approval to a third party.
TestMachine confirmed the bug and shared its findings with Ledger while declining any financial bounty.
Ledger CTO Responds
Charles Guillemet, Ledger's Chief Technology Officer, criticized the public disclosure as fear-mongering, stating that Ledger's in-house hacking team, Donjon, had already detected the issue and shipped a fix.
Public changelog records indicate that version 1.22.2 of the Ethereum app was released on August 12 with a brief note stating "Security issues." However, Ledger did not issue a dedicated security bulletin for the flaw, leaving a communications gap prior to TestMachine's public disclosure.
Guillemet argued that TestMachine contacted the bounty program only after the patch had already been deployed and accused the firm of manufacturing attention rather than conducting responsible security research. TestMachine acknowledged the speed of the fix while proceeding with its public thread.
Action Required for Users
Ledger devices share core code across models including the Nano X, Nano S Plus, Stax, and Apex. Users can secure their devices by opening Ledger Live, updating the Ethereum app, and verifying that the version reads 1.22.2.


