Ledger patches Ethereum app transaction-replacement flaw
Security & Exploits ·
The company says no wallets were compromised, but is urging all users to update firmware and the Ethereum app to version 1.22.3 or later.
Ledger's security team, Donjon, confirmed a transaction-replacement vulnerability in the Ethereum app but said it had already been identified and fixed internally, in version 1.22.2, released August 13, before any public disclosure. The bulletin detailing the issue has been posted on Ledger's Donjon security site since that date. According to the statement posted on X, the vulnerability that circulated publicly was a lab reproduction on an outdated app version, not evidence of a live compromise.
The flaw came to wider attention after OneKey disclosed a vulnerability in Ledger's Ethereum app that allowed transaction signing mismatches, prompting concern before Ledger clarified that the issue had already been patched prior to any exploitation. Ledger says there is no evidence of exploitation in the wild and that no user has been hacked as a result of the bug.
Ledger's response leaned on its updateable architecture as the core mitigation: when a vulnerability is found, whether through its own Donjon team or external researchers, every device in the field can be patched remotely. The company frames this as routine practice rather than a one-time fix, citing a continuous cycle of security bulletins and a bug bounty program that works with outside researchers to find and disclose issues before they can be exploited.
Users are advised to update both firmware and the Ethereum app separately, since the two update independently, and to verify the app version directly on the device rather than assuming a firmware update alone resolves the issue. The recommended minimum version is 1.22.3 or later.
Coverage of the episode, including from Decrypt, has emphasized that the vulnerability was disclosed and patched before any real-world use, distinguishing this case from an active exploit. What remains unclear is how many users had not yet updated to the patched version by the time the vulnerability became public, and whether any transaction-replacement attempts were attempted against unpatched devices outside the lab setting described by Ledger.