Crypto News

Ledger fixes Ethereum app bug that could trick users into signing wrong transactions

Ledger fixes Ethereum app bug that could trick users into signing wrong transactions

Ledger updates Ethereum app to fix security flaw

Ledger, a company that makes hardware wallets for storing cryptocurrency, has released an update for its Ethereum app. The update fixes a bug that could trick users into signing a different transaction than the one shown on their device screen.

The bug was discovered by a security company called TestMachine. They found that a malicious app connected to the Ledger device could start a second transaction while the user was still reviewing the first one. This could make the device show one transaction on the screen but sign a completely different one.

Ledger users should update their Ethereum app to version 1.22.2 to protect themselves from this issue.

What the bug could do

  • The bug affected how the Ledger device handled transaction signing, which is the process of approving a cryptocurrency transaction.
  • A malicious app with special access could replace the transaction details in the device's memory without the user noticing.
  • The device screen would still show the original transaction details, but the device would sign the replaced transaction instead.
  • This could potentially allow attackers to steal funds or perform unauthorized transactions.

What Ledger did to fix it

Ledger released version 1.22.2 of its Ethereum app on August 12, 2026. The update adds two important safeguards:

  • The app now blocks new signing requests while a transaction is already being reviewed.
  • The app now checks that it's still in the correct signing state before approving a transaction.

These changes prevent the specific attack described by TestMachine, where a second transaction could replace the first one during the signing process.

Which devices were affected

The security company TestMachine confirmed the bug existed on the Ledger Flex device. However, they also said that the same code is used across multiple Ledger models, suggesting the bug could affect:

  • Ledger Nano X
  • Ledger Nano S Plus
  • Ledger Stax
  • Ledger Apex
  • Ledger Flex

Ledger's official app manifest for version 1.22.2 lists all these models as build targets, meaning they could all be affected by the bug.

What is still unclear

  • It's not clear when the bug first appeared in Ledger's Ethereum app, as the earliest affected version hasn't been disclosed.
  • There's some disagreement about who discovered the bug first. Ledger says its own security team found it before TestMachine reported it, while TestMachine claims it discovered the issue independently.
  • It's not confirmed whether all affected Ledger models have received the update through the Ledger Wallet software.

Why this matters for Ledger users

Hardware wallets like those made by Ledger are designed to keep cryptocurrency safe by storing private keys offline. The device screen is meant to be a trusted way to verify transaction details before signing. This bug could have undermined that trust by showing false information on the screen.

While there are no reports of this bug being exploited in the real world or any funds being lost, it's an important reminder to:

  • Keep your Ledger device's software up to date.
  • Always carefully review transaction details on your device screen before approving.
  • Only connect your Ledger device to trusted apps and websites.

What Ledger users should do now

Ledger users should immediately check their Ethereum app version and update to 1.22.2 if they haven't already. This can be done through the Ledger Live software. Ledger also recommends keeping all device firmware, apps, and connected software up to date.

This bug is separate from other security issues Ledger has faced in the past, such as a 2023 incident involving a malicious JavaScript library and a separate flaw in the Zilliqa app that could expose private keys.

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!