Ledger has resolved a bug affecting certain transparent transaction signing scenarios within its Ethereum application, according to Chief Technology Officer Charles Guillemet.

There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.

There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability…

— Charles Guillemet (@P3b7_) August 23, 2026

Guillemet clarified that the issue was identified by the Donjon division utilizing a set of AI tools designed for vulnerability detection. The fix has already been implemented in version 1.22.2.

According to Guillemet, users who have updated their firmware and applications are fully protected.

The vulnerability involved the processing of streams in the Ethereum app's APDU commands. In this scenario, a malicious smart contract could theoretically alter transaction data at the moment of signing.

For instance, a user might believe they are confirming a small transfer, while they are, in fact, approving unlimited access for an attacker's address.

Guillemet criticized the public disclosure of the issue, stating that the external company sought a reward only after the fix was released, failed to discuss the case with the program team, and then published a thread that suggested the problem was unresolved.

For example, user X, under the alias TestMachine, detailed the potential mechanics of transaction substitution.

The CTO of Ledger described the situation as a "violation of the principles of responsible vulnerability disclosure."

It is worth noting that on August 13, hardware wallet manufacturer Trezor reported a data breach affecting the personal information of 13,689 users, attributed to a hack of its logistics partner ShipMonk.