Ledger says a flaw in certain Ethereum clear signing flows was patched before public disclosure. TestMachine says it found a live weakness that could let a malicious app change what a user thought they were approving. Same bug? Same timeline? That’s where the mess starts.
- Ledger says the bug was already fixed
- TestMachine says it found a live signing flaw
- The dispute centers on clear signing and APDU messages
- No confirmed theft tied to this issue has surfaced
The basic timeline is the whole game here. On Aug. 23, Ledger Chief Technology Officer Charles Guillemet said the company’s internal security team, Ledger Donjon, found the bug and shipped a fix about two weeks earlier. TestMachine, meanwhile, says its Azimuth system found the issue during an autonomous scan and validated it on a Ledger Flex.
So Ledger’s position is simple: patched first, disclosed later. TestMachine’s position is just as clear: it found a live weakness that was still worth warning about. Those are not the same claim, and the public reporting does not fully settle which timeline is cleaner.
“It was fixed and deployed two weeks ago, ”
Guillemet also brushed off claims that the issue remained active as “manufacturing fear for attention.” Blunt? Yes. Subtle? Not in the slightest. But that’s the mood when a hardware-wallet vendor thinks it is being accused of leaving users exposed after the fix was already out the door.
What the flaw is supposed to do
The dispute centers on clear signing, the hardware-wallet feature meant to show transaction details in readable form before the user approves them. In theory, that helps users verify what they are actually signing instead of staring at a wall of cryptic data and hoping for the best.
TestMachine’s claim is that a malicious application could interfere while the user was reviewing the original transaction and send a competing command through the communication layer between the connected app and Ledger’s Ethereum app. That communication layer uses APDU, short for Application Protocol Data Unit, which is the message format apps use to talk to hardware devices.
In plain English: if an attacker can mess with that exchange, the wallet may be fed misleading instructions. In the worst case, the device could prepare one action while the screen suggests another. That is exactly the kind of gap clear signing is supposed to reduce, but only if the displayed details truly match the payload being signed.
One example described in the reporting was a limited transaction being swapped for a broader token approval. That matters because a token approval gives a contract permission to spend tokens on your behalf. Hand that permission to the wrong app or contract, and the attacker may be able to drain assets within the approved limit. No drama needed. That’s just how bad approvals turn into dead wallets.
Why hardware-wallet users should care
This is not the same thing as a private-key leak. That distinction matters a lot. A signing-display bug is serious because it undermines the user’s ability to verify what they are approving. A private-key exposure is worse because it can turn into full wallet takeover.
Ledger’s own guidance warns that blind signing remains risky because the device cannot present every smart-contract action in readable form. That warning is not marketing fluff. It is the ugly truth behind much of crypto UX: if the wallet cannot explain the transaction, the user is trusting software they may not understand.
Ethereum tried to improve that problem with ERC-7730, a standard for human-readable transaction summaries. Ledger helped develop it before stewardship moved to the Ethereum Foundation. That makes this dispute especially relevant, because it sits right at the intersection of wallet security and the push to make approvals less of a guessing game.
What Ledger says, and what it did not say
Ledger says current firmware and applications protect users. It also says users with the latest Ledger Wallet software, device firmware, and installed Ethereum application are covered. That update path matters. Updating only the desktop or mobile interface does not necessarily replace an outdated app already running on the hardware device.
What Ledger did not publish is just as important. There was no detailed technical advisory naming affected versions, no full exploit write-up, and no precise public checklist showing exactly what conditions were required to make the flaw work. That leaves users and security researchers with a familiar problem: reassurance without enough detail to independently verify the boundaries of the fix.
Ledger’s public Ethereum application repository showed several security-related changes during August, including fixes involving signing states, application context handling, and message finalization. But the public record does not clearly identify which change maps to the disclosed flaw, or exactly when the patched release reached the device app store.
What TestMachine says
TestMachine says it shared and verified the finding with Ledger but declined a bounty. Ledger disputes that framing, saying the bounty program was contacted after the fix had already been shipped and that the researchers did not discuss the issue with the bounty team before publishing claims that suggested it remained unresolved.
That’s the real fight here: not just whether a bug existed, but whether it was still active when the public warning went out. Security disclosure has always been a tug-of-war between getting credit, getting users patched, and avoiding unnecessary panic. Sometimes the result is good security. Sometimes it is a very expensive game of “who said what first?”
TestMachine also said the issue was validated on a Ledger Flex and that shared code could make other models relevant, including Nano X, Nano S Plus, Stax, and Apex devices. That may be a real concern, but it is still a claim rather than a fully demonstrated cross-device exploit. At publication time, there was no complete public proof of concept showing fund theft across every named device.
What is known, and what is still murky
By Aug. 24, no independently verified reports of funds stolen through this specific vulnerability had emerged. That is good news, but it is not the same as saying the problem was harmless. Plenty of serious bugs never show up in a neat theft report, especially when the affected vendor may have patched quickly or when attackers keep their hands off a fresh target.
The unresolved questions are the ones that matter most: which Ledger Ethereum app versions were affected, which exact patch fixed it, whether the flaw could be triggered reliably across different models, and whether the fix fully closes every APDU-related signing manipulation path. Until those details are public, the story remains a mix of credible risk, vendor denial, and incomplete technical visibility.
The bottom line is not “hardware wallets are broken.” That would be lazy nonsense. The better read is that hardware wallets are strong tools, but they are not magic talismans. They depend on firmware, app logic, transaction display quality, and user hygiene. If any one of those layers lies, the whole promise gets weaker.
Key takeaways
-
Was the Ledger Ethereum flaw already fixed?
Ledger says yes. Charles Guillemet said the bug was fixed and deployed about two weeks before his Aug. 23 statement. -
What did TestMachine claim?
TestMachine said it found and validated a flaw that could let a malicious app interfere with clear signing and alter what the user saw versus what was being prepared for approval. -
Were funds confirmed stolen?
No independently verified reports of theft tied to this specific vulnerability had surfaced by Aug. 24. -
What should Ledger users update?
Ledger Wallet software, device firmware, and the installed Ethereum application. Updating only the desktop or mobile app may not be enough if the hardware-device app is outdated. -
Why does clear signing matter so much?
It lets users read what they are approving instead of signing blind. If that display can be manipulated, the security model starts to wobble. -
What is still unknown?
The exact affected versions, the precise exploit path, and whether the patch fully closes every relevant signing-manipulation scenario remain unclear.
Ledger fixes vulnerability in Ethereum app's signing flows. Ledger Ethereum App Bug Affected Clear Signing. Ethereum Pushes Clear Signing Standard to Kill Blind. Ethereum Clear Signing Uses ERC-7730 to End Blind Signing and Wallet Scams. Ledger says it fixed the issue before public disclosure. TestMachine says it found a live flaw worth sounding the alarm over. Both can’t be fully right on timing, and the missing technical details are exactly what keeps this from becoming a clean yes-or-no case. Until a proper security advisory lands, this sits in the usual crypto-security gray zone: real risk, incomplete facts, and plenty of noise around the parts that matter most.