Security1 distinct publisher2 min readPublished
Ledger's CTO says the Ethereum clear-signing fix shipped two weeks before disclosure. The public release record cannot confirm that, and an autonomous scanner chose the publication date.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The verification problem here is structural rather than rhetorical. Ledger can push Ethereum app updates through the device's own app store without cutting a matching tagged release on GitHub [15]. So the newest public tag sitting at version 1.22.1, dated May 27, 2026, with one listed change about instability in APDU communication handling, is not evidence that a patch was never shipped [13]. What it does establish is arithmetic: 88 days separate that tag from the Aug. 23 statement that a fix had gone out two weeks earlier [19], and no August tag names the substitution issue at all [14]. Ledger has also published no technical advisory, no affected-version list and no patched release identifier, leaving "keep firmware and apps updated" as the entire instruction set [17]. That guidance cannot be checked, which is the same thing as saying users cannot check themselves.
The defect itself is a trust-boundary race. TestMachine describes a malicious application sending a competing command while the user is still reading the legitimate transaction, so the screen shows one thing while another is queued for signature [4]. The example the researchers offered is a narrow transaction swapped for a broad token approval [5]. Clear signing exists precisely so the amounts, addresses and contract actions a user approves are rendered on the device instead of the paired software [3], so a display that can be desynchronised from the payload removes the feature's only reason to exist.
The disclosure fight is where the precedent sits. TestMachine says its scanner Azimuth found and validated the flaw during an autonomous scan on a Ledger Flex [6], and that the company shared and verified the finding with Ledger but declined a bounty [10]. Declining the bounty is the load-bearing detail, because bounty terms are the standard instrument vendors use to control publication timing. Guillemet's account is that the bounty program was contacted only after the fix shipped, and that the vulnerability was never discussed with the bounty team beforehand [11]. His counter-claim is that Ledger Donjon had already found the same problem using an AI-powered vulnerability research system of its own [8]. Neither sequence has been independently confirmed [12]. Both sides, notably, credit a machine with the discovery; what they disagree about is scheduling.
For an owner, the practical residue is small and awkward. The patched app is described as available through Ledger Live, but updating the desktop or mobile interface may leave the stale application installed on the hardware, which has to be updated from the device's own app store [18]. No theft through this specific flaw has been independently verified [2].
Ranked by verification strength, evidence, and original report placement.
Ledger has not published a detailed technical advisory, affected-version list or patched release identifier; its guidance, echoed by Guillemet, is to keep firmware and apps updated.
As of Aug. 24, 2026, there were no independently verified reports of funds stolen through the specific vulnerability.
Clear signing is a security feature that displays transaction amounts, addresses and smart-contract actions directly on a Ledger device before approval.
TestMachine said a malicious application could send a competing command while a user was reviewing the legitimate transaction, so the device screen could display one transaction while another was prepared for signing.
Researchers cited a potential example in which a limited transaction could be replaced with a broader token approval.
TestMachine said its AI vulnerability scanner, Azimuth, discovered and validated the flaw during an autonomous scan on a Ledger Flex.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single outlet, competing unverified accounts
One publisher carries the cluster, and its strongest verifiable artifact is a negative one: the public repository's newest Ethereum app tag is 1.22.1 from May 27, 2026 with no August tag naming the issue. The core factual dispute — when the fix shipped and how disclosure was coordinated — rests entirely on competing statements the article itself says are unconfirmed, and there is no advisory, CVE, patched version identifier or complete proof of concept to anchor severity.
Patch state unmeasurable
The supplied material contains no data on how widely the asserted fix has reached devices: no patched version number, no affected-version list, no update or install figures, and no count of exposed devices. The only artifacts are a May 2026 tagged release unrelated to the described issue and an uncorroborated statement that a fix was deployed, which cannot be converted into an uptake measurement without inference.
Severity framing ahead of artifacts
Claims on both sides run modestly ahead of what is demonstrated. The researcher side asserts a multi-device clear-signing bypass found autonomously by an AI scanner without a complete proof of concept for fund theft, while Ledger asserts a shipped fix and dismisses continuing concern as fear-mongering without publishing a version or advisory. The offsetting factor is that the reporting is unusually restrained — it repeatedly states there are no verified thefts and that a missing GitHub tag does not prove a missing patch — which keeps the gap positive but small.
Vendor reputation versus scanner showcase
Both principals have visible stakes in the framing. Ledger's CTO defends the security reputation of the product line and characterizes contrary claims as manufacturing fear for attention, while also asserting parallel internal AI discovery by Ledger Donjon. TestMachine's disclosure doubles as a demonstration of its Azimuth AI scanner and it declined a bounty, removing the confidentiality constraint a bounty would normally impose. The publication timing was effectively set by the party promoting the tooling.
Low — one outlet, unresolved core facts
Confidence is limited by single-publisher sourcing and by the fact that the load-bearing questions (patch date, patched version, device breadth, disclosure order) are all explicitly unresolved in the material. What can be held with reasonable confidence is narrow: the existence of the dispute, the absence of verified thefts as of Aug. 24, 2026, the state of the public release record, and the user-side instruction to update the on-device Ethereum app.
invest
Coinkite now makes Coldcard owners roll dice, after $130M walked out of air-gapped wallets1 distinct publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
invest
Robinhood Chain's first month: a stock-token network that traded cats1 distinct publisher
invest
Standard Chartered puts Hong Kong's regulated HKD stablecoin behind the bank counter1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026