What actually happened to Ledger's Ethereum app

Ledger's Ethereum app had a race-condition bug in its "clear-signing" flow — the screen on your device that's supposed to show exactly what you're approving before you sign it. In practice, a malicious dApp could exploit the timing gap so the transaction you approved on-screen wasn't the one that actually got signed, potentially with far broader permissions than you intended. That's the ledger ethereum vulnerability fix now making headlines, and the good news up front is that Ledger's security research team, Donjon, found and patched it on August 12 — using an AI-assisted scanning tool, according to the company. No bulletin went out at the time.

The story resurfaced this week because a separate security firm, TestMachine, says it independently found and verified the same bug on a Ledger Flex, then published its findings publicly on August 23–24. That's roughly two weeks after Ledger's fix shipped, which is the crux of what's actually being argued about right now.

Is my Ledger safe right now?

For most people, yes — with one important caveat. This wasn't a seed-phrase compromise or a way to drain wallets remotely; exploiting it required you to be interacting with a malicious dApp during the window before the patch existed. If you've updated the Ethereum app on your physical device since mid-August, the specific bug in question is closed. No independently confirmed theft tied to this flaw has surfaced as of this week.

The caveat is coverage: Ledger says the Ethereum app fix also "could potentially" apply to other devices sharing the same underlying code — Nano X, Nano S Plus, Stax and Apex — beyond the Flex model TestMachine tested. There's no public, per-device confirmation that each of those has been patched and verified. That gap, not the original bug, is the live open question.

Why Ledger and TestMachine disagree on the timeline

Ledger CTO Charles Guillemet said publicly on August 23 that the company's own fix predated TestMachine's report by about two weeks, and that TestMachine only contacted Ledger's bug-bounty program after the patch had already shipped, without discussing the vulnerability with the bounty team before publishing — he called the public disclosure "manufacturing fear for attention" rather than responsible research. TestMachine's own account is narrower: it says its AI scanning tool, Azimuth, found and verified the bug independently on a Ledger Flex during an autonomous scan, that it shared and verified the finding with Ledger's team, and that it declined the bounty reward it was offered.

Neither account has been independently confirmed in full. What matters for a reader isn't who's right about the timeline — it's that the dispute, not the vulnerability itself, is the actual news this week. The technical risk was mostly resolved on August 12. The trust question — did Ledger handle disclosure properly, and should it have published a bulletin at the time — is still open, and it's a fair one given how hardware-wallet users are supposed to rely on transparent security communication.

Do I need to do anything about the ledger ethereum vulnerability fix?

One step, and it's easy to miss: updating Ledger Live, the companion app on your phone or computer, does not automatically update the Ethereum app installed on the physical device itself. Those are two separate pieces of software. To actually get the fix, you need to open the app catalog on your Ledger device through Ledger Live, find the Ethereum app, and reinstall or update it there. If your device already shows a recent Ethereum app version (anything from mid-August 2026 onward), you're covered for this specific issue.

Beyond that, there's no fund migration, no new wallet, and no reason to move assets to a different device. The exploit path required active interaction with a compromised or malicious application during a narrow window that's now closed for updated devices. If you rarely check your device's installed app versions, this is a reasonable prompt to do it once, not a reason to panic.

The risk most coverage is getting wrong

A lot of the alarm around this story treats it like a fund-loss event, when the more accurate read is closer to a disclosure and communications dispute. No verified thefts have been tied to this bug, and the fix has been live for roughly two weeks. That's meaningfully different from, say, a live exploit with confirmed victims.

What would change that read: a working proof-of-concept exploit published publicly, or confirmation that one of the other device models — Nano X, Nano S Plus, Stax, Apex — never actually received the patch despite Ledger's assurance. Either of those would convert this from a reputational story about how Ledger talks about security to an active-exposure story about what it failed to fix. Watch for a formal Ledger security bulletin listing exactly which devices and app versions are covered; the absence of one so far is arguably the more legitimate criticism than the timeline dispute itself. Until then, the base case is that this stays a story about trust and disclosure practices, and the practical takeaway for anyone holding a Ledger device is simply to confirm the on-device Ethereum app is current.

Sources