Ledger CTO Charles Guillemet said on Aug. 23, 2026, that the company had fixed a clear-signing flaw in its Ethereum app two weeks before security firm TestMachine publicly disclosed the issue. As of Aug. 24, there were no independently verified reports of funds stolen through the specific vulnerability.
The issue involved clear signing, a security feature that displays transaction amounts, addresses, and smart-contract actions directly on a Ledger device before approval. TestMachine said a malicious application could send a competing command while a user was reviewing the legitimate transaction. Under that scenario, the device screen could display one transaction while another was prepared for signing. Researchers cited a potential example in which a limited transaction could be replaced with a broader token approval.
TestMachine said its AI vulnerability scanner, Azimuth, discovered and validated the flaw during an autonomous scan on a Ledger Flex. Because of shared code, the company said Nano X, Nano S Plus, Stax and Apex devices could also potentially be affected. However, no complete public proof of concept showing fund theft across every named device was available at publication.
Guillemet said Ledger Donjon, the company’s internal security research team, had independently identified the problem using an AI-powered vulnerability research system. He said the fix “was deployed two weeks ago” and argued that claims the vulnerability remained open amounted to “manufacturing fear for attention.”
TestMachine disputed that account, saying it had shared and verified the finding with Ledger but declined a bounty. Guillemet said the company contacted Ledger’s bounty program only after the fix had shipped and did not discuss the vulnerability with the bounty team before publication. Neither side’s account of the disclosure sequence has been independently confirmed.
TestMachine, Ledger and the Missing Release Record
Ledger’s public Ethereum app repository creates another unresolved question. As of Aug. 24, its newest tagged release was version 1.22.1, dated May 27, 2026. Its only listed change was “Instability in APDU communication handling.” No August 2026 tagged release identifies the clear-signing substitution issue described by TestMachine.


That does not establish that Ledger failed to patch the flaw. Ledger can distribute application updates through its device app store without creating a corresponding tagged GitHub release. Still, the public record does not allow users to verify Guillemet’s “two weeks ago” timeline or determine which Ethereum app version contains the fix, as CoinLaw reports.
Ledger has also not published a detailed technical advisory, affected-version list, or patched release identifier. Its guidance, echoed by Guillemet, is to keep firmware and apps updated.
What Users Need to Check for the Ethereum App Vulnerability?
The patched Ethereum app has been described as available through Ledger Live, but updating the desktop or mobile interface alone may not replace an outdated application installed on the hardware wallet. Users therefore need to check the device’s own app store and reinstall or update the Ethereum app separately.
The incident also highlights why clear signing matters. Verifying transaction details on the hardware device itself, rather than relying solely on the paired software, is intended to protect users from transaction manipulation.
The Ledger discussion should not be treated as evidence of confirmed losses from this flaw. At this stage, the facts establish a disputed disclosure timeline, an asserted fix, and a lack of independently verified theft—not confirmation that funds were lost or that the patch was never shipped.
For TestMachine, Ledger and users alike, the unresolved issue is documentation. A dated, versioned security advisory identifying the affected versions and patch would allow users to verify their protection without relying on competing public statements.

