Share
Subscribe to the AlphaWire Newsletter
AI security firm TestMachine says its autonomous agent found a Ledger Ethereum app flaw that could let a malicious dApp replace a transaction while a user was still reviewing it on the device. The disclosure quickly turned into a dispute with Ledger CTO Charles Guillemet, who says the company’s Donjon team had already found and patched the same bug.
Ledger’s own changelog confirms Ethereum app version 1.22.2 shipped on Aug. 12 with only “Security issues” listed under fixes, 10 days before TestMachine’s Aug. 22 post. That confirms the patch predates the disclosure, but the public record doesn’t identify the flaw or establish who discovered it first.
Ledger’s clear-signing documentation says the device converts encoded transaction data into human-readable details that users can verify before approving. TestMachine said its Azimuth AI agent found that the Ethereum app could still accept a second Application Protocol Data Unit, or APDU, command while the first transaction was under review.
Found by Azimuth during an autonomous scan of the Ledger Ethereum app. Validated on Flex. Shared and verified with the team. Declining any bounty. Same shared APDU/UI code across Nano X, Nano S Plus, Stax, Apex.
The power of always on securityhttps://t.co/fH5mO97Kkp
— TestMachine (@testmachine_ai) August 22, 2026
In that scenario, a malicious dApp could replace the transaction being signed while the device continued showing the original details. TestMachine said it validated the flaw on a Ledger Flex and pointed to shared APDU and user-interface code across Nano X, Nano S Plus, Stax and Apex.
The reported attack path didn’t require extracting private keys. Exploitation still depended on a malicious or compromised dApp being able to communicate with the Ledger device during transaction review.
Ledger’s changelog gives no detail beyond “Security issues” for version 1.22.2. Donjon’s public security-bulletin index still ends at LSB 022, a Monero key-recovery flaw published June 4, with no bulletin describing the Ethereum issue.
Guillemet said Donjon found the flaw independently using its own AI tools. He also accused TestMachine of “manufacturing fear for attention,” arguing that the firm approached Ledger’s bounty program only after the patch had shipped. TestMachine, for its part, said the flaw was shared and verified with Ledger and that it declined a bounty.
There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.
There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability…
— Charles Guillemet (@P3b7_) August 23, 2026
The public evidence settles the patch date, not the discovery dispute. Ledger’s Ethereum app version 1.22.2 was released on Aug. 12, 10 days before TestMachine disclosed the flaw.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share