A vulnerability in the Ethereum application of the Ledger hardware wallet allowed a device to show the user one transaction while ultimately signing a different one.
The issue was reported on August 21, 2026, by the TestMachine team, which indicated that it had been found during an autonomous scan of the application and validated on a Ledger Flex device.
According to TestMachine, EVERY Ledger running the Ethereum application is vulnerable to signature substitution. The attack can occur when a malicious decentralized application has access to WebHID (this is the technology that allows a dApp from the browser to communicate directly with the Ledger device and send commands during signing).
During the review of a transaction, the attacker can send commands to substitute the operation that would ultimately be signed, without modifying what the user sees on the device screen.
As an example, TestMachine describes a scenario where the user initiates sending 0.01 ETH to another address from a decentralized application. Ledger shows that operation during the review, and the user can approve it. However, the Ledger could end up signing an authorization that allows the attacker to spend a maximum amount of DAI (which was the token used for the example).
The cause, according to the explanation published by TestMachine, is related to command management while the review interface remains open.
TestMachine points out that the problem is present in Nano X, Nano S Plus, Stax, and Apex devices. The investigation was shared and verified with the Ledger team, according to the publication.
The change log on GitHub shows that Ledger incorporated in version 1.22.2, dated August 12, 2026, fixes identified generically as security issues.
Among the changes are measures directly related to the described flaw, such as rejecting signature commands received while a review is pending, fixing the signing mode set at the start of the operation, and rejecting changes during the continuation fragments of a signature.
Validations of the application state were also added in the signature approval functions and protections against concurrent flows in different operations.
TestMachine indicated that, indeed, the fix corresponds to Ethereum app 1.22.2 and recommended updating via Ledger Live once the patch is available.
However, according to the information provided by that security company, the corrected version is still not available for download from Ledger Live, so the danger remains latent.
The origin of the finding and the current status of the patch have generated conflicting reports between the research company and the manufacturer. TestMachine maintained that it detected the vulnerability through its autonomous scanner Azimuth and recommended updating to version 1.22.2 of the Ethereum application.
For his part, Ledger's Chief Technology Officer (CTO), Charles Guillemet, stated that the error affected certain clear signing flows, but assured that it had already been identified and corrected two weeks ago by Ledger Donjon, the company's internal security team, using artificial intelligence tools. Guillemet noted that the patch is indeed deployed and available for users.
If you keep your apps updated, you are protected. That's the whole story, Guillemet stated on his official X account.
The executive also questioned the behavior of the research firm regarding disclosure practices: This company contacted our bounty program after the patch had already been sent and did not follow responsible disclosure; in fact, they never spoke with the bounty program team. They then published a thread implying that the problem was not resolved.
In light of the contradictory reports, it may be useful for Ledger users to verify that version 1.22.2 has indeed been correctly installed before continuing to perform operations with these devices.
Such issues become particularly relevant following the hack of Coldcard hardware wallets that occurred at the end of July, resulting in the theft of over 2,000 bitcoins (BTC), as reported by CriptoNoticias.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























