Ledger fixed a clear-signing race condition in its Ethereum app on August 12, 2026, but disclosed nothing publicly until security firm TestMachine independently found and published the same flaw ten days later, prompting a dispute over what responsible disclosure should look like.
Read the full story: Ledger Patched a Clear-Signing Flaw, Then Stayed Quiet →
Transcript
Ledger's whole pitch is that what you see on the device screen is what actually gets signed. On August twelfth, a race condition broke that promise. A malicious app could fire a second signing command while you reviewed a transaction, so the screen showed one transfer while a different one got signed underneath. Ledger fixed it that same day, in Ethereum app version one twenty two point two, and said nothing publicly. Ten days later, security firm TestMachine found the same class of bug and disclosed it, using an AI agent called Azimuth. Ledger's CTO fired back, saying it was already fixed and TestMachine was manufacturing fear for attention. Nobody has confirmed a single case of stolen funds. But the silence is exactly what let this fight happen. If you sign Ethereum transactions on a Ledger, check that your app is on version one twenty two point two or later, right now.