Ledger patched a vulnerability in its Ethereum app (fixed in v1.22.2) that could let a malicious web application exploit a race condition to swap transaction data after review, potentially turning benign actions into harmful approvals. While no private keys or firmware were compromised and no confirmed losses are reported, the incident highlights operational risk for Ethereum/ERC-20 users interacting with dApps via WebHID and may depress near-term risk appetite on ETH-linked activity.
Impact level
● Medium
Affected assets
ETH/USDT-1.67%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Ledger has released a critical security patch for its Ethereum application following the discovery of a vulnerability that could compromise "clear signing" integrity. On Aug. 24, 2026, security firm TestMachine published an analysis detailing a race condition in APDU command handling that allowed malicious web applications to swap transaction data in memory while the device display remained unchanged. Although Ledger CTO Charles Guillemet stated that the internal Ledger Donjon team identified the flaw and prepared a fix by Aug. 12, 2026, the update became widely visible alongside TestMachine's report. The vulnerability affects Ledger Flex, Nano X, Nano S Plus, Stax, and Apex devices running Ethereum app versions prior to 1.22.2. While no exploits have been confirmed, users are urged to update via Ledger Live and review existing token approvals to mitigate potential risks from previously granted permissions.