Crypto news report · source clearly identified

Ledger patches Ethereum clear‑signing vulnerability

Ledger says it fixed a vulnerability affecting certain Ethereum clear signing flows and urged users to update their firmware and applications.

Ledger has released a firmware and application update that addresses a vulnerability in the Ethereum app’s clear‑signing flows. The fix was deployed before the issue was publicly disclosed by a third‑party security researcher.

What the flaw affected

The bug related to “clear signing,” a feature that shows transaction details on the Ledger device screen so users can verify amounts, addresses and smart‑contract actions before approving a transaction. TestMachine, the security firm that reported the issue, claimed a malicious application could inject a competing command during the review, potentially causing the device to display one transaction while signing another.

Timeline and disclosure dispute

Ledger’s chief technology officer, Charles Guillemet, stated that the internal security team (Ledger Donjon) discovered the flaw using an AI‑based research system and that a patch was shipped roughly two weeks before his public comment on August 23, 2026. TestMachine contended that it found the issue via its Azimuth AI scanner and validated it on a Ledger Flex, then reported it to Ledger’s bounty program. Guillemet said the researchers did not discuss the finding with the bounty team before publishing claims that the problem remained unpatched.

Devices and scope

The vulnerability was said to potentially affect multiple Ledger models, including Flex, Nano X, Nano S Plus, Stax and Apex. Ledger’s public repository shows several security‑related changes to the Ethereum app in August, though it does not label which change corresponds to the clear‑signing fix.

Impact and user guidance

  • No confirmed thefts linked to this specific vulnerability have been reported as of August 24, 2026.
  • Users with the latest firmware and Ethereum app version are protected.
  • Updating only the desktop or mobile wallet software is insufficient; the hardware device’s application must also be updated.
  • Users should continue to verify transaction details on the device screen and avoid blind signing when possible.

Broader context

The incident differs from a prior signing flaw affecting Zilliqa, which exposed private keys and could not be retroactively fixed. Ledger previously contributed to the ERC‑7730 standard for human‑readable Ethereum transaction summaries.

Source & attribution

News Source

Publisher
crypto.news
Original date
August 24, 2026, 5:39 AM
Original headline
Ledger says Ethereum signing flaw was already fixed
View original report ↗