Critical Ledger Vulnerability Allows Transaction Substitution in Ethereum App

Critical Ledger Vulnerability Allows Transaction Substitution in Ethereum App

First seen 24 Aug 2026, 05:15 UTC WeexCryptobriefing 71% similarity 67.5

Article Content

Browse articles
ThreatCluster

A vulnerability in Ledger's Ethereum application allows malicious dApps to swap legitimate transactions for harmful ones during signing. Reported by TestMachine on August 21, 2026, the flaw affects all Ledger devices running the Ethereum app, including Nano X, Nano S Plus, Stax, and Apex. The issue arises from a race condition in the APDU command sequence, enabling attackers to exploit timing windows to replace transaction data without user awareness. Ledger's internal security team identified and patched the vulnerability on August 12, 2026, but public awareness only emerged after TestMachine's disclosure. Despite the patch, users are advised to update to version 1.22.2 of the Ethereum app, as the fix was not initially available for download. Ledger's CTO downplayed the severity of the issue, asserting that users running the latest version are protected. No reports of actual exploitation or funds lost have been confirmed.

Key Points: • A vulnerability in Ledger's Ethereum app allows transaction substitution during signing. • The flaw affects all Ledger devices running the Ethereum app and was patched on August 12, 2026. • Public awareness of the vulnerability increased after TestMachine's disclosure on August 21, 2026.

ThreatCluster AI How this analysis works

Timeline

2026-08-12
Patch released for Ethereum app vulnerability
Ledger deployed version 1.22.2 to fix a race condition bug affecting transaction signing flows.
Cryptobriefing
2026-08-21
Vulnerability publicly disclosed by TestMachine
TestMachine reported the transaction substitution vulnerability, detailing how it could be exploited by malicious dApps.
Weex
2026-08-23
Public awareness of vulnerability increased
Following TestMachine's disclosure, Ledger's CTO responded to concerns about the vulnerability's severity and impact.
Weex

Community

Browse all →