Ledger fixes clear-signing flaw in Ethereum app, two weeks old
Security & Exploits ·
Ledger's chief technology officer said a vulnerability affecting certain clear-signing flows in the company's Ethereum app was identified and patched two weeks ago.
Charles Guillemet, Ledger's CTO, said the issue was discovered internally by Ledger Donjon, the company's security research unit, and resolved before it became public knowledge, according to a report from Wu Blockchain. Users who keep their Ledger firmware and applications updated to the latest versions are protected, Guillemet said.
The flaw sat within clear-signing mechanisms, the process that lets hardware wallet users review transaction details before approving them on-device, rather than blindly signing opaque data. A defect in this flow could in theory affect how transaction information is verified or displayed prior to signing, though the report does not specify further technical detail beyond the fix being applied to the Ethereum app.
Guillemet also said a firm describing itself as a "smart contract security" company disclosed the vulnerability only after Ledger had already deployed the fix, and subsequently suggested the issue remained unresolved. The claim adds a layer of dispute over disclosure timing, though the material does not name the firm or detail the basis for its later characterization.
A separate account of the episode, corroborating the core timeline, similarly describes the vulnerability as patched two weeks ago and confirms that devices running current firmware are not exposed, per a post shared on X. Two sources in total describe the same sequence of discovery, patch, and later disclosure.
Unresolved from the available material is the identity of the security firm that raised the post-patch alarm, the specific technical mechanism of the vulnerability, and whether any user funds or transactions were affected before the fix was deployed. Ledger's own account frames the matter as closed for updated users, but the dispute over disclosure timing and the firm's later claims remain unaddressed in the reporting so far.