Ledger Closes a Gap in the Ethereum App: When the Display Shows Something Other Than What You Sign
Ledger has closed a flaw in its Ethereum app that let a malicious application swap the reviewed transaction for a different one. Anyone holding Ether or ERC-20 tokens on the device should check the app version and clear out old token approvals.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Anyone who owns a Ledger and uses it to manage Ether or ERC-20 tokens should open Ledger Live and check which version of the Ethereum app is installed on the device. Anything older than 1.22.2 is missing a security fix. That fix closes a flaw which undermined the very promise a hardware wallet is bought for: that the screen shows what the device is about to sign.
The case became public on August 24, 2026, when the security firm TestMachine published its analysis. The fix itself already existed by that point. Between the two dates lies a dispute over who found the flaw first and when Ledger shipped it. For you as an owner, that dispute is secondary. What matters is the version number on your device and the question of which approvals you granted in the past.
Ledger security vulnerability in the Ethereum app: what actually happened
Neither the device firmware nor the custody of the private key was affected. The problem sat in the Ethereum app: the small piece of software you install on the device in addition, for Ether and ERC-20 tokens. It prepares a transaction, displays it to you and collects your confirmation.
In the faulty version, that sequence could be thrown out of order. A malicious web application with access to the connected device could send a second signing command while the first transaction was still on screen awaiting review. The app then swapped the data in memory without bringing up a fresh review screen. The harmless transfer you had just examined remained on the display. Your confirmation, however, applied to the swapped data.
According to the security researchers, the pattern has been demonstrably reproduced on a Ledger Flex. Because the devices largely share the Ethereum app's program code, the Nano X, Nano S Plus, Stax and Apex are also considered potentially vulnerable. Ledger has not disclosed which version of the app first contained the error; the researchers' comparison starts at 1.22.1, the previously tagged version from May 27, 2026.
Clear signing explained: why the display is the real security promise
Clear signing refers to showing the complete transaction data in plain text on the hardware wallet's display before you confirm: recipient address, amount, and in the case of contract calls, the action the contract is meant to perform.
This is the reason such a device makes sense in the first place. Your computer may be compromised, your browser may render a manipulated interface, the website may be a fake. As long as the device in your hand has its own screen, independent of the computer, and shows the real data there, any manipulation becomes visible before you press the button. The private key never leaves the device; it does not need to, because the device signs for itself.
The flaw struck exactly this chain at its weakest point. The key stayed safe, the firmware was untouched, and yet a different consent could end up being given than the one you had read. A device whose display can no longer be read as binding is, on this one point, no better than a software wallet on an infected machine. If you want to revisit the difference between the two designs, you will find it in our software wallet comparison and in the hardware wallet comparison.
Race condition and APDU commands: the technical core of the flaw
A race condition is a bug in which the outcome depends on which of two roughly simultaneous commands gets processed first. Such bugs are treacherous, because the program code looks correct on its own and the sequence runs cleanly in the vast majority of cases. They only surface when someone deliberately engineers the order.
APDU is the command format in which smart cards and hardware wallets talk to the connected computer. Every step of a signature consists of several such commands. The Ethereum app carried a state alongside them, recording which transaction was currently up for review. That state could be overwritten while the review was still running.

WebHID in the browser: why a website talks to your device at all
WebHID is a browser interface that lets a website communicate directly with a connected USB device once you have explicitly granted permission. Without it, a hardware wallet could not be used conveniently inside a decentralised application; with it, the website sits closer to the device than many users realise.
The attack described requires that you have already granted this access to a manipulated or hijacked site and that you initiate a transaction there. It does not work remotely against a device sitting in a drawer. That limits the circle of those affected considerably, though it does not diminish the finding: anyone who works regularly with decentralised exchanges, bridges or staking interfaces grants this access all the time.
Hardware wallets comparedToken approval instead of transfer: why unlimited approvals are so dangerous
The damage in a swap of this kind rarely comes from the transfer itself. It comes from what can be slipped in to replace it.
A token approval is the permission granted to a smart contract to dispose of a certain quantity of your tokens in future, without you confirming each individual debit again. Many applications request this permission on an unlimited basis for the sake of convenience. An approval once granted does not expire and remains in force until you explicitly revoke it.
The difference between a transfer and an approval
A transfer costs you exactly the amount you confirm. An unlimited approval costs you, in the worst case, the entire balance of the token concerned, at a moment of the recipient's choosing. That is why swapping a small transfer for a far-reaching approval is the most rewarding attack on a signing path. How attackers collect these approvals in practice is something we set out in our piece on wallet drainers and signature approvals.
Updating the Ethereum app to 1.22.2: the route through Ledger Live
Version 1.22.2 closes the route described with two locks. The app refuses a new signing session while a review is in progress, and it rejects an incoming confirmation if the state no longer matches what was displayed. The version entry sits in the release overview of the Ethereum app at Ledger; the note there lists only fixed security issues as its content, without describing the flaw.
The update itself is unspectacular. You connect the device, open the manager for installed applications in Ledger Live and update the Ethereum app there. Existing balances are unaffected, because the keys are derived from your recovery phrase and do not reside in the app. Removing and reinstalling the app costs you no coins either.
How to identify the installed version
Ledger Live shows the version number for each application in the device manager. If it reads 1.22.2 or higher, the fix is in place. If it reads 1.22.1 or older, it is missing. A glance at the version number of Ledger Live itself is not enough.
Why a firmware update does not update the Ethereum app with it
This is the point at which the case most often goes wrong in practice. Firmware, Ledger Live and the individual coin apps are maintained separately and updated separately. Someone who updates the device firmware and comes away feeling reassured may still have an outdated Ethereum app on the device.
The same separation explains why reports on wallet security so often talk past each other. In the Coldcard case the error lay in the generation of the seed, right down at the foundations, which is why a new seed was needed there. The BitBox vulnerabilities concerned the firmware. Here the error sits one level above that, in a replaceable application, and so an app update is sufficient. Your recovery phrase does not need to be regenerated in this case.

Checking and revoking token approvals: the second step after the update
The update protects future signatures. It does not clear up what was granted in the past. If you have worked with decentralised applications over recent months, it is worth looking at the open approvals on your address.
Block explorers and specialised interfaces list, for a given address, which contracts are allowed to dispose of which tokens. Approvals to contracts you no longer use can be revoked one by one. A revocation is an ordinary transaction and incurs network fees, which is why the clean-up is best done in quiet periods with low fees. If you want to keep an eye on the Ether price while doing so, you will find our assessment in the Ethereum price prediction.
One side effect that hardly anyone thinks about: every revocation appears in your transaction history and generates fees. Those who document their movements cleanly have an easier time at the next tax return; the common tax and portfolio tools read such events in automatically.
Software wallets comparedThe disclosure dispute between Ledger and TestMachine
There are two accounts of the sequence of events, and they do not match. Both are reproduced here as the accounts of the respective party; neither has been independently confirmed.
Ledger's chief technology officer Charles Guillemet stated that the in-house security lab Ledger Donjon had found the error itself, and that the fix was shipped roughly two weeks before publication. TestMachine, he said, only came forward to the bug bounty programme afterwards. He characterised the security firm's statements as generating fear in order to attract attention.
TestMachine counters that its own testing system, named Azimuth, discovered the weakness during an automated run on a Ledger Flex, and that the results were shared with Ledger. At the time of publication, in the firm's view, no fix was available.
The verifiable individual facts sit somewhere in between. The changelog entry for version 1.22.2 carries the date August 12, 2026, the signed tag in the source repository August 13. It only became visible as a published release around August 24, however, at the same time as the security firm's analysis. A user who wanted to check in the meantime whether a fix existed could not find it there. The technical reconstruction of the sequence, including these dates, was assembled by CryptoSlate.
Have funds been lost? What is known about the damage
Based on the information provided so far by both sides, there is no confirmed case in which the flaw was actually exploited. No losses are documented, and reading out private keys was not possible by this route in any event.
That is good news with a caveat that has to be stated alongside it. A signature obtained this way would look on chain like any other voluntary signature. An affected user would only notice the event once tokens later flowed out, and would then probably attribute it to ordinary phishing. The absence of confirmed cases therefore does not allow the conclusion, with any certainty, that there were none. That is an assessment, not a documented statement.
What the case says about hardware wallets and self-custody
It would be the wrong conclusion to turn this episode into a rejection of hardware wallets. The attack required device access already granted and a malicious application, it left the key untouched, and it has been fixed.
The useful conclusion is a different one. A hardware wallet moves trust from the computer to a small device with its own screen, and that device consists of firmware, applications and companion software, all maintained separately. Security at this point is not a state you acquire with the purchase, but an upkeep you perform. That includes keeping applications current, tidying up approvals regularly and, for large holdings, adding a second layer of confirmation. Which class of device suits which holding is something we broke down after the Coldcard case in our piece which hardware wallet now?
Checking the Ledger Ethereum app: what to take away
- Check the version and update it. Connect the device, open the device manager in Ledger Live and check the Ethereum app. Anything below 1.22.2 needs updating, and a firmware update alone will not do it. Which devices handle this separation in which way is shown in the hardware wallet comparison.
- Clear out open token approvals. Have your address checked for which contracts may dispose of your tokens, and revoke everything you no longer need. If you conclude in the process that you want a separate address with a small balance for daily use, the software wallet comparison will help with the choice.
- Document the movements. Revocations and reallocations generate fees and show up in your history. Record them as you go, rather than reconstructing them next spring; the tax and portfolio tools take the import work off your hands.
(As of August 25, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Revoke Token Approvals on Ethereum: A Revocation Now Costs 0.52 Cents
- End Blind Signing: What to Check on Your Hardware Wallet After the Trezor Update
- Wallet Drainers: What You Really Approve When You Confirm, and How to Take It Back
- D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
- Reporting Duty for Wallet Makers: What Has Applied Since September 11, 2026
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 25, 2026 1:47 PM

Magic Eden and Limit Break exploit: 530 WETH and thousands of NFTs drained, how to revoke your approvals
A bug in Limit Break's Payment Processor, the protocol behind Magic Eden's former Ethereum marketplace, has been draining NFTs and WETH since Thursday. Our blockchain analysis shows 911 affected wallets. What happened, why hardware wallets do not protect you and which two approvals to revoke now.
August 31, 2026 10:12 AM

Fake AML Checks for Crypto Wallets: How to Spot the Scam Sites
Fraudulent websites pose as money-laundering screening services for crypto addresses and ask you to connect your wallet. A genuine check needs only the public address, and three of the domains named by Malwarebytes still respond twelve days later.
December 22, 2020 3:49 PM

Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Ledger, a cryptocurrency wallet provider has encountered a data breach. The official Twitter account of the hardware wallet tweeted that they have been alerted to the dump of a client database.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
May 17, 2023 7:40 PM

WARNING: Ledger can read Private keys – New Controversial Feature?
Ledger alternatives: Let's explores the details of the new private key extraction feature, and the reasons behind the concerns it has generated.
June 8, 2021 9:41 PM

How to send Ethereum from Metamask?
MetaMask was initially available in desktop web browser extensions for Google chrome and firefox. Later in 2020, they released its mobile app version which is available in Android and iOS. MetaMask was audited by legal authorities & found to be exceptionally secure and user-friendly.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
January 20, 2025 1:50 PM

Ethereum Price Prediction with Vitalik Buterin New Leadership after ETH Price Struggles in Bitcoin's Shadow
ETH price struggles with Bitcoin’s dominance, Trump’s crypto moves, and the Solana blockchain surge. As Vitalik Buterin announces leadership changes to reshape Ethereum’s future, what to expect for Ethereum price and blockchain?
April 25, 2024 11:44 AM

Beware of New Ethereum Node Scam: USDT Fraud Exposed
Crypto Scammers exploit Ethereum nodes and USDT to deceive crypto users. How are they pulling it off and what essential tips can help you protect yourself against these crypto scams?
March 31, 2026 5:13 PM

Quantum Threat to Bitcoin? Google Research Sparks Urgent Crypto Security Debate
Google’s quantum breakthrough raises fears for Bitcoin security. Can crypto survive quantum attacks—or is an upgrade urgent?
August 3, 2022 9:22 AM

What are the BEST Ethereum Wallets in 2022?
What are the best Ethereum wallets in 2022? In this article, we talk about the best Ethereum wallets for 2022 and help you pick the best.
March 12, 2020 1:12 PM

What Is A Cold Wallet? And Why Is It Important?
A cold wallet is a wallet which is completely offline and used for storing cryptocurrencies. It is also known as cold storage.
September 28, 2026 7:16 AM

Ethereum Gas at One Cent: What Gwei and Etherscan Mean for Your ERC20 Transfers
An ether transfer cost around one cent on September 27, 2026, while a swap on a decentralised exchange cost eight. This guide explains how gas is billed in gwei, what to look up on Etherscan and which three mistakes are the most common in an ERC20 transfer.
August 22, 2026 4:34 PM

BitBox02: Firmware 9.26.5 Closes Three Security Vulnerabilities. What to Check Now
BitBox released firmware 9.26.5 on August 17, 2026, closing three security vulnerabilities in the BitBox02 and BitBox02 Nova. Existing seeds are not affected according to the manufacturer; an update is due anyway, and with unused devices the order matters.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
April 21, 2026 2:00 PM

LayerZero Security Alert: Is Your Crypto Safe After the $292M KelpDAO Exploit?
A $292M exploit on KelpDAO exposes a massive LayerZero vulnerability. With 47% of apps at risk, are your assets still safe in the crypto space?
December 14, 2023 3:12 PM

BREAKING News: Ledger Library Compromised, Urgent Security Alert for Multiple DApps and Ledger Users
In a shocking turn of events, the widely used Ledger library has been compromised, posing a significant threat to funds.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
April 27, 2026 10:30 AM

Win $5,000 in BTC: Tangem Launches Exclusive 2026 Prize Draw
Tangem announces a massive prize draw with $5,000 in BTC and iPhone 17s up for grabs. Secure your crypto and enter today using our exclusive link.
November 2, 2021 11:14 AM

Comparison Between Ledger And Trezor Wallet
A crypto wallet works just like your physical wallet, but is also virtual. In this article, we will be looking at the Ledger and Trezor Crypto Wallets.
December 28, 2018 3:02 PM

How To Use a Trezor Wallet?
Trezor is a hardware wallet which gives exceptional security for managing Bitcoin and other cryptocurrencies private keys.It incorporates and deposits personal keys securely and enables users to carry trade without an Internet link. Trezor grants its users with numerous benefits, […]
October 2, 2026 7:16 AM

$1.26 Billion in Three Months: Crypto Hacks Hit Their 2026 High
The security firm CertiK counts around $1.26 billion in damage from 247 incidents for the third quarter of 2026. September was the worst month of the year with 99 cases, and this is the background and what it means for your custody.
September 14, 2026 4:10 AM

Foreign Code on Your Ethereum Address: How to Check Your EIP-7702 Delegation
Since the Pectra upgrade, a single signature can be enough for your Ethereum address to run the code of someone else's contract. Our own measurement across 200 blocks shows what these delegations mostly point to today, and how to check your own address in a few minutes.
More from CryptoTicker
