SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
A machine found the bug and set the clock: Ledger disputes TestMachine's timeline
Ledger's CTO says the Ethereum clear-signing fix shipped two weeks before disclosure. The public release record cannot confirm that, and an autonomous scanner chose the publication date.
The Watch · Security desk

What happened
- Ledger's CTO said on Aug. 23 that the company had already fixed an Ethereum app clear-signing flaw two weeks before TestMachine published it.
- TestMachine says a malicious app could inject a competing command while the user reads the legitimate transaction, so the screen and the signed payload diverge.
- No theft through this particular vulnerability had been independently verified as of Aug. 24.
Why it matters
- exposure Shared code puts Nano X, Nano S Plus, Stax and Apex owners inside the question with no public proof of concept for any of them, so they cannot size their own risk either way.
- constraint Without a version identifier, a user has no way to distinguish a patched Ethereum app from an unpatched one, which turns the fix into something taken on trust.
- precedent A scanner that refuses the bounty is a reporter the vendor cannot put on an embargo, and the disclosure calendar moves to whoever is running the scan.
- contradiction Both parties claim AI-assisted discovery and neither timeline is confirmed, so the reader's judgement rests on which unverifiable account they find more plausible.
The verification problem here is structural rather than rhetorical. Ledger can push Ethereum app updates through the device's own app store without cutting a matching tagged release on GitHub [13]. So the newest public tag sitting at version 1.22.1, dated May 27, 2026, with one listed change about instability in APDU communication handling, is not evidence that a patch was never shipped [11]. What it does establish is arithmetic: 88 days separate that tag from the Aug. 23 statement that a fix had gone out two weeks earlier [16], and no August tag names the substitution issue at all [12]. Ledger has also published no technical advisory, no affected-version list and no patched release identifier, leaving "keep firmware and apps updated" as the entire instruction set [1]. That guidance cannot be checked, which is the same thing as saying users cannot check themselves.
The defect itself is a trust-boundary race. TestMachine describes a malicious application sending a competing command while the user is still reading the legitimate transaction, so the screen shows one thing while another is queued for signature [4]. The example the researchers offered is a narrow transaction swapped for a broad token approval [5]. Clear signing exists precisely so the amounts, addresses and contract actions a user approves are rendered on the device instead of the paired software [3], so a display that can be desynchronised from the payload removes the feature's only reason to exist.
The disclosure fight is where the precedent sits. TestMachine says its scanner Azimuth found and validated the flaw during an autonomous scan on a Ledger Flex [6], and that the company shared and verified the finding with Ledger but declined a bounty [8]. Declining the bounty is the load-bearing detail, because bounty terms are the standard instrument vendors use to control publication timing. Guillemet's account is that the bounty program was contacted only after the fix shipped, and that the vulnerability was never discussed with the bounty team beforehand [9]. His counter-claim is that Ledger Donjon had already found the same problem using an AI-powered vulnerability research system of its own [19]. Neither sequence has been independently confirmed [10]. Both sides, notably, credit a machine with the discovery; what they disagree about is scheduling.
For an owner, the practical residue is small and awkward. The patched app is described as available through Ledger Live, but updating the desktop or mobile interface may leave the stale application installed on the hardware, which has to be updated from the device's own app store [15]. No theft through this specific flaw has been independently verified [2].
What to watch
- Whether Ledger publishes a dated advisory or tagged release naming the affected and patched Ethereum app versions.
- A complete public proof of concept showing fund theft on Nano X, Nano S Plus, Stax or Apex, which would change the severity read.
- Whether other wallet vendors rewrite bounty terms to cover submissions from autonomous scanners that set their own publication dates.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+24
- Incentives72
- Confidence36
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Ledger has not published a detailed technical advisory, affected-version list or patched release identifier; its guidance, echoed by Guillemet, is to keep firmware and apps updated.
- [2]
As of Aug. 24, 2026, there were no independently verified reports of funds stolen through the specific vulnerability.
- [3]
Clear signing is a security feature that displays transaction amounts, addresses and smart-contract actions directly on a Ledger device before approval.
- [4]
TestMachine said a malicious application could send a competing command while a user was reviewing the legitimate transaction, so the device screen could display one transaction while another was prepared for signing.
- [5]
Researchers cited a potential example in which a limited transaction could be replaced with a broader token approval.
- [6]
TestMachine said its AI vulnerability scanner, Azimuth, discovered and validated the flaw during an autonomous scan on a Ledger Flex.
- [7]
TestMachine said that because of shared code, Nano X, Nano S Plus, Stax and Apex devices could also potentially be affected, and no complete public proof of concept showing fund theft across every named device was available at publication.
- [8]
TestMachine disputed Ledger's account, saying it had shared and verified the finding with Ledger but declined a bounty.
- [9]
Guillemet said TestMachine contacted Ledger's bounty program only after the fix had shipped and did not discuss the vulnerability with the bounty team before publication.
- [10]
Neither side's account of the disclosure sequence has been independently confirmed.
- [11]
As of Aug. 24, 2026, the newest tagged release in Ledger's public Ethereum app repository was version 1.22.1, dated May 27, 2026, whose only listed change was "Instability in APDU communication handling."
- [12]
No August 2026 tagged release identifies the clear-signing substitution issue described by TestMachine.
- [13]
Ledger can distribute application updates through its device app store without creating a corresponding tagged GitHub release.
- [14]
The public record does not allow users to verify Guillemet's "two weeks ago" timeline or determine which Ethereum app version contains the fix, as CoinLaw reports.
- [15]
The patched Ethereum app has been described as available through Ledger Live, but updating the desktop or mobile interface alone may not replace an outdated application installed on the hardware wallet, so users need to check the device's own app store and reinstall or update the Ethereum app separately.
- [16]
88 days elapsed between the May 27, 2026 tagged release of Ethereum app 1.22.1 and Guillemet's Aug. 23, 2026 statement.
- [17]
Ledger CTO Charles Guillemet said on Aug. 23, 2026, that the company had fixed a clear-signing flaw in its Ethereum app two weeks before security firm TestMachine publicly disclosed the issue.
- [18]
Guillemet said the fix "was deployed two weeks ago" and argued that claims the vulnerability remained open amounted to "manufacturing fear for attention."
- [19]
Guillemet said Ledger Donjon, the company's internal security research team, had independently identified the problem using an AI-powered vulnerability research system.
Sources
1 independent publisher whose own reporting we read for this story.
- thecyberexpress.comLedger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed
1 article · August 25, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Ethereum Transaction SigningFollow
- Coordinated Vulnerability DisclosureFollow
- AI-Driven Vulnerability ResearchFollow
- Hardware Wallet SecurityFollow
- Security Advisory TransparencyFollow