Ledger just closed a dangerous gap in how its hardware wallets handle Ethereum transactions. The Ledger Ethereum wallet fix patches a flaw in the device’s signing process. A malicious app could swap a small, approved transfer for a hidden request to drain a user’s tokens. Anyone who signs Ethereum transactions on a Ledger device benefits from the update, even if they never noticed the risk.
How the Flaw Worked
Ledger’s Ethereum app shows users a transaction before they approve it on the device screen. The bug lived in a race condition. A rogue application could intercept that approval step and substitute a different transaction right after the user said yes. Someone confirming a tiny token transfer could unknowingly grant unlimited spending access to an attacker’s wallet address instead.
The flaw touched Ledger’s full hardware lineup: Flex, Nano X, Nano S Plus, Stax, and Apex. It lived in the Ethereum app itself, not the companion software. Updating the phone or desktop app alone didn’t fix anything. Users had to push new firmware directly to the device.
Two Security Teams Found the Same Bug
Ledger’s internal security group, Donjon, used AI-assisted testing tools to catch the flaw first. The team shipped a silent fix on August 12, rolling out Ethereum app version 1.22.2 without a public bulletin. Security firm TestMachine found the identical issue independently, using its own AI agent, and published its findings between August 21 and 23. That two-week gap sparked a debate over how loudly wallet makers should announce a fix before every user has installed it.
Why the Ledger Ethereum Wallet Fix Matters
Hardware wallets exist to stop exactly this kind of attack. They’re supposed to keep signing safe even when the software around them can’t be trusted. A flaw that lets an attacker rewrite what a user approves undermines that entire promise. Closing it restores the core guarantee hardware wallets are built on: what you see on the screen is what you actually sign.
The incident also shows how AI tools are reshaping wallet security research. Two separate teams, running two separate AI agents, landed on the same critical bug within weeks of each other. That’s a preview of how fast both attackers and defenders can now move. Cryptonomist first reported the fix and disclosure timeline in detail.
Ledger isn’t the only team tightening up Ethereum-adjacent software this month. Besu recently closed five flaws in Ethereum’s own execution client. The pattern across the ecosystem looks consistent: security teams are finding bugs faster, often with AI assistance, and shipping fixes before attackers can drain real wallets.
What Ledger Owners Should Do
Anyone holding a Ledger device should open Ledger Live, check the installed Ethereum app version, and update to 1.22.2 or later directly on the hardware. Confirming a transaction only stays safe when the app doing the confirming runs the latest code.
