Cryptobriefing
Critical Ledger Vulnerability Allows Transaction Substitution in Ethereum App
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
A vulnerability in Ledger's Ethereum application allows malicious dApps to swap legitimate transactions for harmful ones during signing. Reported by TestMachine on August 21, 2026, the flaw affects all Ledger devices running the Ethereum app, including Nano X, Nano S Plus, Stax, and Apex. The issue arises from a race condition in the APDU command sequence, enabling attackers to exploit timing windows to replace transaction data without user awareness. Ledger's internal security team identified and patched the vulnerability on August 12, 2026, but public awareness only emerged after TestMachine's disclosure. Despite the patch, users are advised to update to version 1.22.2 of the Ethereum app, as the fix was not initially available for download. Ledger's CTO downplayed the severity of the issue, asserting that users running the latest version are protected. No reports of actual exploitation or funds lost have been confirmed.
Key Points: • A vulnerability in Ledger's Ethereum app allows transaction substitution during signing. • The flaw affects all Ledger devices running the Ethereum app and was patched on August 12, 2026. • Public awareness of the vulnerability increased after TestMachine's disclosure on August 21, 2026.