Ledger patched Ethereum clear-signing bug before TestMachine disclosure, CTO says

Ledger users should update the Ethereum app to version 1.22.2 after official code changes showed that a malicious dApp or other connected host could start a second signing command while a transaction was still under review, so pressing approve could return a signature for substituted data instead of the details shown on screen. Security firm TestMachine said on Aug. 22 that the path required WebHID access, could replace the transaction held in memory without opening a new review, and was validated on Ledger Flex, with shared code and build targets also covering Nano X, Nano S Plus, Stax and Apex. Ledger’s changelog dates 1.22.2 to Aug. 12, 2026 and GitHub shows a signed tag on Aug. 13; the release closes the path by refusing a new signing session during an active review and rejecting an approval callback when state no longer matches. CTO Charles Guillemet said on Aug. 23 that Ledger Donjon found a bug in certain clear-signing flows and deployed the fix about two weeks earlier, before TestMachine contacted the bounty program, while TestMachine said Azimuth found the issue, shared and verified it with Ledger, and on Aug. 22 still described the fix as not yet released. Public sources report no confirmed in-the-wild exploitation, lost funds or private-key extraction, and give no firmware minimum specific to this flaw.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.