Ledger Fires Back at Ethereum App Accusations: What Are They Hiding Behind the Curtain of Controversy?

Ledger Fires Back at Ethereum App Accusations: What Are They Hiding Behind the Curtain of Controversy?

So, here’s the kicker: Ledger’s Ethereum app found itself in the hot seat—not for a headline-worthy innovation, but because of a vulnerability that had the crypto community buzzing. Imagine trusting a hardware wallet—the fortress for your digital fortune—only to discover that what you sign isn’t exactly what flashes on the screen. Sounds like a nightmare, right? Ledger’s CTO, Charles Guillemet, stepped up to squash the frenzy, revealing that the bug was patched up quietly weeks before a certain security firm, TestMachine, threw the issue into the public arena. But why didn’t Ledger wave a flag about it when the fix dropped? In the world of crypto security, timing and transparency can make or break trust, and this episode highlights just how fragile that balance can be. If you’re keeping your ETH stash snug with Ledger, it’s time to double-check those updates and maybe, just maybe, rethink how much faith you put in bug bounty drama. LEARN MORE

The Ledger Ethereum [ETH] app has caught the spotlight, but not for good reasons. According to Ledger’s CTO Charles Guillemet, there has been a vulnerability in the app, which has been pushed by a “smart contract security” company and concerns the Ledger signers.

However, Guillemet took to X on the 23rd of August and clarified that the issue “was fixed and deployed two weeks ago.”

Though the vulnerability was fixed in Ethereum app version 1.22.2 on the 12th of August, the controversy arose because Ledger did not publicly explain the vulnerability when it released the patch.

Ledger vs. TestMachine

The controversy revolved around a security flaw that caused the user to sign something different from what they saw on Ledger’s screen.

That is particularly serious because the main security advantage of a hardware wallet is that the device itself allows users to verify the transaction before approving it.

A security researcher called TestMachine later disclosed the issue publicly. This is what led to a dispute between the researcher and Ledger over whether the disclosure was responsible or unnecessarily alarming.

Now, since Ledger had already discovered the issue using Ledger’s Donjon security team and AI-powered tools, Guillemet took to X and clarified,

This company [TestMachine] reached out to our bounty program after the fix was already shipped, and did not follow responsible disclosure, they actually never discussed with the bounty program team.

He added,

Then they published a thread implying the problem is unsolved. It is not. That’s not security research. That’s manufacturing fear for attention.

What’s more?

This is where ERC-7730 comes into the picture, which aims to improve how transaction information is displayed and verified on wallets. Fortunately, there are no reported cases of funds being stolen through this specific vulnerability.

However, users are advised to update their Ledger firmware and Ethereum app and continue verifying transactions on the device before signing.

This comes on the heels of the Coldcard exploit, wherein Ledger also gained attention. However, Ledger clarified that the Coldcard vulnerability was specific to Coldcard’s firmware and did not compromise Ledger’s Bitcoin hardware wallets.


Final Summary

  • The controversy was mainly FUD, which revolved around a security flaw in Ledger’s Ethereum app.
  • Ledger had already discovered the issue before the outside company publicly disclosed it.

Post Comment

WIN $500 OF SHOPPING!

    This will close in 0 seconds