Cryptobriefing Ledger Ethereum App Vulnerability Allows Transaction Substitution
Article Content
- •A critical vulnerability allowed transaction substitution in Ledger's Ethereum app.
- •The flaw was patched on August 12, 2026, but details were disclosed publicly only on August 21.
- •Users must update to Ethereum app version 1.22.2 to remain secure.
Ledger has addressed a significant vulnerability in its Ethereum app that could allow malicious decentralized applications (dApps) to substitute legitimate transactions with harmful ones during the signing process. This flaw, identified by Ledger's internal security team, was patched in version 1.22.2 on August 12, 2026. Users who have updated their Ledger firmware and Ethereum app are protected, while those using outdated versions remain at risk. The vulnerability was disclosed publicly by the TestMachine security team on August 21, leading to confusion over the patch's availability. Ledger's CTO criticized the timing of the disclosure, emphasizing that the issue was resolved before it became widely known. The vulnerability affects all Ledger devices running the Ethereum app, including Nano X, Nano S Plus, Stax, and Apex. Users are urged to update their applications via Ledger Live to ensure security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track Ledger in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which Ledger devices are affected?
What should users do to protect themselves?
Is there any evidence of exploitation?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…