Skip to content
Ledger Ethereum App Vulnerability Allows Transaction Substitution

Ledger Ethereum App Vulnerability Allows Transaction Substitution

First seen 24 Aug 2026, 05:15 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 25, 2026 at 02:53 UTC
  • •A critical vulnerability allowed transaction substitution in Ledger's Ethereum app.
  • •The flaw was patched on August 12, 2026, but details were disclosed publicly only on August 21.
  • •Users must update to Ethereum app version 1.22.2 to remain secure.

Ledger has addressed a significant vulnerability in its Ethereum app that could allow malicious decentralized applications (dApps) to substitute legitimate transactions with harmful ones during the signing process. This flaw, identified by Ledger's internal security team, was patched in version 1.22.2 on August 12, 2026. Users who have updated their Ledger firmware and Ethereum app are protected, while those using outdated versions remain at risk. The vulnerability was disclosed publicly by the TestMachine security team on August 21, leading to confusion over the patch's availability. Ledger's CTO criticized the timing of the disclosure, emphasizing that the issue was resolved before it became widely known. The vulnerability affects all Ledger devices running the Ethereum app, including Nano X, Nano S Plus, Stax, and Apex. Users are urged to update their applications via Ledger Live to ensure security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-08-12
Patch for Ethereum app vulnerability released
Ledger released version 1.22.2 to fix a flaw allowing transaction substitution during signing.
Cryptorank
2026-08-21
Vulnerability publicly disclosed
TestMachine reported the vulnerability, highlighting the potential for transaction substitution in Ledger's Ethereum app.
Weex
2026-08-24
Ledger CTO addresses user concerns
Charles Guillemet reassured users that those on the latest app version are protected and criticized the disclosure timing.
Finance.Biggo

More articles in this cluster (13)

Following this threat?

Track Ledger in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Ledger devices are affected?
All Ledger devices running the Ethereum app, including Nano X, Nano S Plus, Stax, and Apex, are affected.
What should users do to protect themselves?
Users must update their Ledger firmware and Ethereum app to version 1.22.2 via Ledger Live.
Is there any evidence of exploitation?
No confirmed reports of exploitation have surfaced; the vulnerability was patched before public disclosure.