Ledger Says Ethereum App Flaw Patched Before Public Disclosure
Ledger has confirmed that a critical vulnerability in its Ethereum application, which could have allowed malicious actors to manipulate transaction details during user approval, was patched two weeks before a security researcher publicly disclosed the issue. The company's Chief Technology Officer, Charles Guillemet, stated on August 23 that the fix was deployed on August 12, 2026, and accused the researcher of "manufacturing fear for attention." The flaw affected the "clear signing" process, a security feature designed to display transaction information in a human-readable format on the Ledger device screen.
Verilumia