A critical vulnerability that could have allowed hackers to drain a crypto wallet during a single transaction in Ledger’s Ethereum app has been flagged as of August 26.
This design flaw was publicly disclosed around August 23, 2026, by TestMachine, an Artificial Intelligence (AI)-powered security research team. However, the bug was initially found by Ledger’s own internal security team, Donjon, which used AI-powered vulnerability detection tools.
“There was a bug concerning certain clear signing flows. It was found by the Donjon team using their AI-powered vulnerability research suite. It was fixed and deployed two weeks ago. If you keep your Ledger apps up to date, you are protected,” Charles Guillemet, Ledger CTO, stated.
Ledger patched this vulnerability quietly on August 12 with version 1.22.2. Furthermore, this bug allowed malicious decentralized applications (DApps) to swap a harmless transfer for an unlimited token approval, granting backdoor access to a
We współpracy z: https://finbold.com/critical-vulnerability-discovered-in-ethereum-app-on-ledger-wallets/