Ledger discloses two Ethereum-app flaws fixed in version 1.22.3
Ledger's new security bulletins describe clear-signing and swap-validation flaws affecting earlier Ethereum-app releases; the company says it has no evidence either was exploited against users.
By The Third AnglePublished 3 min read
Illustrative hardware-wallet imagery; it does not depict a Ledger security advisory or a specific device model. Photo: Unsplash · Unsplash License
Ledger's chief technology officer, Charles Guillemet, said an Ethereum-app bug affecting certain clear-signing flows had already been fixed and deployed before security company TestMachine made its public disclosure. Guillemet's Aug. 23 statement on X says Ledger's Donjon team found the issue with AI-assisted vulnerability research and that users with current firmware and applications are protected.
The dispute matters because clear signing is meant to show readable transaction details on the hardware device before approval. TestMachine's public disclosure says a malicious application could send a competing command during the review flow, potentially creating a mismatch between what the user saw and what was prepared for signing.
The new advisory names affected versions
Ledger's Security Bulletin 024 says Ethereum-app versions 1.19.0 through 1.22.2 could display only the last item in an attacker-controlled array of 257 operations while signing the full transaction. The bulletin says the flaw required a compromised host and an unusual clear-signing descriptor, and that its proof of concept ran on a private fork with no real funds moved.
A second bulletin, LSB-025, covers a swap-path bug in Ethereum-app versions 1.20.0 through 1.22.2. The app could validate the expected address and quantity without confirming that the operation was actually a token payment, potentially allowing an approval to pass as a payment. Ledger says it has no evidence this issue was exploited against users.
Independent reports from CryptoBriefing and Chain Tech Daily describe the issue as a race condition in the APDU communication path that could allow transaction substitution during a clear-signing flow. Those reports also say no confirmed theft tied specifically to this issue had surfaced by Aug. 24.
Users should update all three layers
Ledger users should update Ledger Wallet, the device firmware and the installed Ethereum application to version 1.22.3 or later, then verify transaction details on the device screen. Updating only the desktop or mobile interface may leave the application running on the hardware device unchanged.
The public record does not establish that funds were stolen, that every named model was exploitable in the same way or that version 1.22.2 is the complete remediation for every possible signing path. Those boundaries require a technical advisory with affected versions, exploit conditions and a patch mapping. The verified news is narrower: Ledger says it found and fixed a clear-signing bug, while TestMachine says it independently identified a related transaction-substitution risk and the two sides disagree over the disclosure timeline.