Crypto news

24.08.2026
08:01

Ledger has closed a critical vulnerability in its Ethereum application: incident details and analysis of responsibility

hack

The world of hardware crypto wallets is uneasy once again. This time, the industry leader—Ledger—has come under the spotlight, having promptly fixed a serious bug in its application for working with Ethereum. The issue concerns a vulnerability affecting "transparent" transaction signing scenarios, where a user could be misled about the actual terms of an operation.

The Core of the Problem: Manipulation of APDU Commands

Ledger's CTO, Charles Guillemet, confirmed that the flaw was discovered by the company's internal division, Donjon. Specialists used their own set of AI tools to search for vulnerabilities, highlighting the growing role of artificial intelligence in cybersecurity. The problem lay in the processing of APDU command streams (Application Protocol Data Unit message format) in the Ethereum application. In theory, a malicious smart contract could substitute transaction data at the moment of signing on the device.

Imagine a scenario: you are confident you are confirming a small transfer of funds, but in reality, your signature authorizes unlimited access to the wallet for an attacker's address. It is precisely this attack vector that made the bug critically dangerous for users actively interacting with DeFi protocols.

Reaction and Fix

The fix has already been deployed in application version 1.22.2. According to Guillemet, users who have installed the latest firmware patches and application updates are fully protected from this threat. However, a significant scandal has erupted around the incident, related to the ethics of information disclosure.

An external company specializing in smart contract security sought a reward only after Ledger had already released the fix. Moreover, they did not contact the bug bounty program team to discuss details, but instead published a public thread creating the false impression that the problem remained unresolved. Guillemet called this a "violation of responsible disclosure principles," which is absolutely fair—such actions undermine trust in the ecosystem and create panic among users.

Context and Conclusions

The incident occurred against the backdrop of other news: in mid-August, Ledger's competitor—Trezor—reported a data breach affecting nearly 14,000 customers due to a hack of its logistics partner, ShipMonk. This reminds us that security in the crypto industry is a comprehensive task involving both software and hardware aspects.

My analysis: Although the vulnerability was closed quickly, the very fact of its existence underscores the complexity of creating truly secure devices for working with decentralized finance. Users should take this as a signal: always check that the firmware and applications on your wallets are up to date. As for the external company's actions in publicly disclosing before coordinating with the vendor—this is a worrying trend that could lead researchers to hide findings rather than report them, ultimately harming everyone.