00:00
Money for You
Money for You
USD/RUB
EUR/RUB
Cryptocurrency

Ledger Disputes Disclosure Timeline After Ethereum App Vulnerability

A standoff has emerged between Ledger and security firm TestMachine over a flaw in the Ethereum application’s clear signing process. While TestMachine claims its AI-driven tool identified a risk to transaction integrity, Ledger’s CTO Charles Guillemet asserts the vulnerability was patched two weeks before the public disclosure.

Ledger Disputes Disclosure Timeline After Ethereum App Vulnerability

The dispute centers on whether the vulnerability remained an active threat. TestMachine, utilizing its Azimuth AI research tool, reported that a malicious application could potentially swap transaction data while a user reviewed their Ledger screen. The firm identified the issue across several models, including the Flex, Nano X, Nano S Plus, Stax, and Apex. Ledger acknowledged a bug existed in specific clear signing flows but maintains that updated firmware and application versions effectively neutralize the threat.

Guillemet criticized the disclosure, labeling the firm’s public warnings as an attempt to generate alarm. He stated that Ledger’s internal security research team, Ledger Donjon, had already identified and resolved the issue using their own AI systems prior to the firm’s contact with the company’s bounty program. Despite the public back-and-forth, no confirmed reports of stolen funds linked to this specific flaw had surfaced by August 24, 2026.

To ensure security, Ledger advises users to update their device firmware and the Ethereum application itself, noting that updating only the interface software is insufficient. While the company has not issued a detailed technical advisory identifying specific affected versions, users are encouraged to maintain vigilance by verifying transaction details on the hardware screen. Blind signing remains a distinct, separate risk, as the device cannot always render complex smart contract interactions in a readable format.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!