The Ledger Ethereum app vulnerability that lit up crypto Twitter this week is already patched — Ledger says so, and the timeline it's citing predates the panic by about two weeks. Security researcher TestMachine (Azimuth) posted a public thread on August 21 describing a flaw in the Ethereum app's clear-signing flow. Ledger's chief technology officer Charles Guillemet rebutted it on X on August 23, calling the framing "manufacturing fear for attention," and coverage widened into Monday, August 24. Both things can be true at once: the bug was real, and it's also already closed for anyone running current firmware.
What Is the Ledger Ethereum App Vulnerability?
The flaw is an APDU race condition. APDU is just the command format a Ledger device uses to talk to whatever software — a wallet app, a browser extension, a dApp — is asking it to sign something. TestMachine found that a malicious website with WebHID access to your device could, in theory, fire a second signing request while your Ledger's screen was still displaying the first one. If the timing lined up, you could end up physically approving a transaction on the device screen that no longer matched what you thought you were signing — for example, an unlimited token approval swapped in for a simple transfer. Clear-signing is Ledger's core safety promise: what you see on the device is what gets signed. A working exploit here would undercut exactly that promise, which is why security researchers took it seriously even after Ledger says it was fixed.
Is My Ledger Safe?
For anyone running Ethereum app version 1.22.2 or later, yes. Ledger's own Donjon security team says it found this bug internally and shipped a fix on August 12 — nearly two weeks before TestMachine's public writeup. The catch is that the changelog for that release didn't name the vulnerability; it listed only a generic "security issues" line, with no advisory and no CVE assigned. That's part of why this turned into a fight rather than a footnote: Ledger fixed something serious without saying clearly what it was, so when TestMachine's disclosure landed, it read like breaking news instead of confirmation of an old fix.
Do I Need to Update?
If you haven't opened Ledger Live and pushed an app update recently, check now — this is the one piece of the story that's genuinely still live risk. Updating Ledger Live itself doesn't patch this; the Ethereum app installed on the device is a separate piece of firmware that needs its own update to 1.22.2 or newer. Open Ledger Live, go to the Manager or My Ledger section, and update the Ethereum app specifically, not just the Ledger Live software shell around it. There's no confirmed count of how many devices are still running the vulnerable version, which is the honest gap in this story: Ledger says the bug is fixed, but it can't say how many users have actually installed the fix, and that tail of unpatched hardware is where the real remaining risk sits.
Did Anyone Lose Funds?
No confirmed thefts tied to this bug have surfaced as of August 24. That matters, because the exploit path required a fairly specific setup — a malicious dApp, WebHID access granted by the user, and precise timing against an unpatched device — rather than something that could be triggered remotely or silently against every holder at once. Combined with the fact that Ledger says it closed the hole two weeks before anyone described it publicly, the realistic window for anyone to have actually been hit looks narrow. That could change if new information surfaces, but nothing reported so far points to real-world losses tied specifically to this flaw.
A Disclosure Fight, Not an Open Exploit
Strip away the noise and what's actually happening is a disagreement about disclosure ethics, not a live technical emergency. TestMachine published its findings without first confirming with Ledger's bug-bounty program whether the issue had already been addressed — standard practice in responsible disclosure is to check with the vendor before going public, precisely to avoid this kind of confusion. Ledger, in turn, is leaning hard on "we already fixed it weeks ago" as its rebuttal, and the technical case for that holds up: the Ethereum app's public commit history for the August 12 release includes specific fixes — rejecting signing commands received mid-review, locking the signing mode at the start of an operation — that line up with the flaw TestMachine described. What's still missing is a named security advisory or CVE tying that release explicitly to this bug, which is the actual gap in Ledger's paper trail, not the code itself.
Expect this to keep playing out as a reputational argument over who owed whom a heads-up, rather than as an unfolding hack. Watch for two things: whether Ledger eventually publishes a formal security advisory naming the bug, which it hasn't done as of August 24, and whether any wallet drain gets traced back to this specific flaw. Neither has happened yet. For now, the practical takeaway for readers doesn't depend on how the disclosure fight resolves: confirm your Ledger Ethereum app is on version 1.22.2 or later, and treat any device you haven't updated recently as exposed until you do.
Sources
- https://www.cryptotimes.io/2026/08/24/ledger-says-it-patched-ethereum-app-flaw-weeks-before-public-warning/
- https://crypto.news/ledger-says-ethereum-signing-flaw-was-already-fixed/
- https://www.kucoin.com/news/flash/ledger-patches-ethereum-app-vulnerability-allowing-transaction-substitution
- https://cryptobriefing.com/ledger-ethereum-app-vulnerability-fix/