Ledger patched a critical Ethereum app flaw on August 12 that could have let attackers drain ERC-20 tokens in one transaction.
Charles Guillemet, Ledger's chief technology officer, said the bug was found by the company's internal security team Donjon using AI-powered vulnerability detection tools and fixed two weeks before the public disclosure. "If you keep your Ledger apps up to date, you are protected," he said.
The flaw allowed malicious decentralized applications to swap a harmless transfer for an unlimited token approval, granting backdoor access to all ERC-20 tokens on users' hardware wallets. TestMachine confirmed the bug on a Ledger Flex using its AI agent Azimuth, which catches 86.3 percent of known bugs with roughly 2.7 percent false positives on its EVMBench benchmark. The same shared APDU/UI code spans the Nano X, Nano S Plus, Stax, and Apex devices.
Chainalysis has traced roughly $1 billion in crypto stolen through approval phishing since May 2021. Ledger has sold more than 7 million devices across 180 countries. While the bug was not exploited, users who have not updated to version 1.22.2 remain exposed.
Guillemet called TestMachine's disclosure "fear-mongering," saying the firm contacted the bounty program only after the patch shipped. "AI-speed research only makes the ecosystem safer if the people doing it still follow basic security principles," he said. "Disclose responsibly. Verify before you publish. Don't confuse noise with a finding." TestMachine declined any bounty and praised the speed of the fix.
The incident follows two other severe Ledger security issues in 2026. A bug in the Zilliqa app, present since 2019, exposed private keys through flawed random number generation and led to the theft of 683 million ZIL from more than 6,700 accounts. Ledger's payment processor Global-e also suffered a data breach earlier this year that exposed customer names and contact information.
The Ethereum app flaw echoes a January 2021 Donjon disclosure that the same app failed to show transaction data for unsupported assets. On-chain sleuth ZachXBT has been critical of hardware wallet companies as AI tools accelerate both attack and defense capabilities. Donjon has published 22 numbered security bulletins, none of which covered this bug.
Ledger users should update the Ethereum app to version 1.22.2 through Ledger Live. The company urged all customers to update to the latest version, though the Nano S is not affected by this specific vulnerability.
AI now surfaces these bugs in hours, while vendors and researchers still coordinate at human speed. That gap is where security disputes like this one live, and it is likely to widen as both sides deploy more machine-learning tools.
This article is for informational purposes only and does not constitute investment advice.