AI Firm Exposes Ledger Bug, CTO Calls It Fear-Mongering After Quiet Fix

An artificial intelligence (AI) security firm went public with a Ledger Ethereum app bug. Ledger says it had already fixed the flaw quietly, two weeks earlier.
Chief technology officer Charles Guillemet called the disclosure fear-mongering. The patch shipped on August 12 with a one-line note and no security bulletin.
What the Ledger Ethereum App Bug Actually Did
Ledger sells one core promise. The screen shows you what you are signing. That promise has a name. Ledger calls it clear signing, and it turns raw transaction code into plain words on the device screen.
TestMachine says it found a way around that. The firm builds an AI agent called Azimuth that hunts exploits in smart contracts. On its own EVMBench benchmark, Azimuth catches 86.3% of known bugs with roughly 2.7% false positives.
Here is the flaw in plain terms. A malicious website could send the device a second command while you were still reading the first one.
The channel between browser and device is called the Application Protocol Data Unit, or APDU. It kept listening during the review. So it accepted the swap.
You would read a small transfer on screen. Then you would tap approve. And you would actually sign an unlimited token approval to a stranger.
That last part is why this matters. Chainalysis has traced roughly $1 billion in crypto stolen through approval phishing since May 2021. Those victims signed the approvals themselves.
TestMachine says it confirmed the bug on a Ledger Flex. Ledger has sold more than 7 million devices across 180 countries.
Ledger’s Donjon Team Says It Got There First
Guillemet flips the timeline. Donjon is Ledger’s in-house hacking team. He says it caught the bug with its own AI tools and shipped the fix first.
The public changelog backs the date. Version 1.22.2 landed on Aug. 12. Its entire security note says “Security issues.”
Donjon has published 22 numbered security bulletins. None of them covers this bug. The latest, dated June 4, deals with a Monero key-recovery issue instead.
That silence is the gap TestMachine walked into. Ledger closed the hole, then never told owners what it had closed.
Guillemet’s sharper complaint is about manners. He says TestMachine contacted the bounty program only after the patch shipped. It never spoke with the bounty team.
“…Then they published a thread implying the problem is unsolved. It is not. That’s not security research. That’s manufacturing fear for attention,” Charles Guillemet, Ledger CTO remarked.
Follow us on X to get the latest news as it happens
TestMachine praised the speed of the fix and turned down the reward. Ledger pays bounties in Bitcoin, at an amount it sets case by case.
AI Found the Bug Twice, But Humans Still Fought
Both sides used machine learning to reach the same defect. That is the part worth watching.
Ledger has made this argument before. Its executives have said for months that AI attackers threaten wallets more than weak hardware does.
Guillemet drew his line at discipline.
“AI-speed research only makes the ecosystem safer if the people doing it still follow basic security principles. Disclose responsibly. Verify before you publish. Don’t confuse noise with a finding.”
The fight itself is familiar. Security firms have gone loud after hacking a Trezor device, and CertiK researchers fought Kraken over disclosure terms in 2024.
So is the flaw. Back in January 2021, Donjon disclosed that this same Ethereum app failed to show transaction data for unsupported assets. Same app, same lesson. What you saw was not what you signed.
AI now surfaces these bugs in hours. Vendors and researchers still coordinate at human speed. That gap is where this argument lives.
For owners, the fix is dull. Open Ledger Live, update the Ethereum app, and check that it reads 1.22.2.
Source: BeInCrypto
Cryptocurrency News
Random quote about money
"Уберечь свои деньги стоит больших трудов, чем добыть их."















* to search the proxy database, just enter a country name, e.g. Russia, USA, Thailand