Ledger fixes critical Ethereum wallet bug before disclosure
Ledger patched a critical Ethereum wallet bug on August 12, 2026, preventing malicious dApps from swapping transactions. The update, released before public disclosure, improved user security and signing processes.
Ledger addressed a critical vulnerability in its Ethereum hardware wallet app on August 12, 2026, before security researchers made the issue public. The flaw, present in version 1.22.1 and earlier, allowed a malicious dApp to swap a transaction during the approval process. This could have tricked users into granting unlimited token allowances instead of the intended transfer. The vulnerability stemmed from a race condition in APDU command handling, enabling a second, malicious command to overwrite the original transaction data while the device still displayed the legitimate transaction. Ledger’s internal security team, Donjon, discovered and resolved the issue, releasing version 1.22.2 with improved signing state management and blocking of competing signing commands during transaction review. Initially, Ledger did not issue a detailed security bulletin, which led to market anxiety and increased demand for alternative security solutions. The fix was later confirmed by Ledger’s CTO, who emphasized the importance of keeping firmware and apps updated to maintain security.