Skip to content

To keep going please Log in.

or

By submitting my information, I agree to the Privacy Policy and Terms of Service.

To keep going please Log in.

or

By submitting my information, I agree to the Privacy Policy and Terms of Service.

To keep going please Log in.

or

By submitting my information, I agree to the Privacy Policy and Terms of Service.

To keep going please Log in.

or

By submitting my information, I agree to the Privacy Policy and Terms of Service.

Critical vulnerability discovered in Ethereum app on Ledger wallets

Critical vulnerability discovered in Ethereum app on Ledger wallets

A critical vulnerability that could have allowed hackers to drain a crypto wallet during a single transaction in Ledger’s Ethereum app has been flagged as of August 26.

This design flaw was publicly disclosed around August 23, 2026, by TestMachine, an Artificial Intelligence (AI)-powered security research team. However, the bug was initially found by Ledger’s own internal security team, Donjon, which used AI-powered vulnerability detection tools. 

“There was a bug concerning certain clear signing flows. It was found by the Donjon team using their AI-powered vulnerability research suite. It was fixed and deployed two weeks ago. If you keep your Ledger apps up to date, you are protected,” Charles Guillemet, Ledger CTO, stated.

Ledger patched this vulnerability quietly on August 12 with version 1.22.2. Furthermore, this bug allowed malicious decentralized applications (DApps) to swap a harmless transfer for an unlimited token approval, granting backdoor access to all ERC-20 tokens on users’ Ledger hardware wallets.

As of press time, this bug had not been exploited, but Ledger users who have not updated to the latest version remain vulnerable. Although this specific vulnerability may not affect Ledger Nano S users, the company urged all its customers to update to the latest version.

Ledger security issues 2026

So far in 2026, the Ledger team has reported two more severe vulnerabilities. For instance, a more serious bug in Ledger’s Zilliqa app, which had existed since 2019, exposed private keys through flawed random number generation and led to the theft of 683 million ZIL from over 6,700 accounts. 

The Zilliqa team first observed suspicious on-chain activity on July 19, 2026, publicly disclosed the vulnerability on July 21, and suspended native ZIL transactions shortly after. This flaw was isolated to the Zilliqa network and did not affect other holdings.

Earlier this year, Ledger’s payment processor Global-e suffered a data breach that exposed customer names and contact information. The notable use of AI by both black-hat and white-hat attackers has significantly changed the software landscape, thus heavy criticism of hardware wallet companies by on-chain sleuth ZachXBT.

Featured image via Shutterstock

Best Crypto Exchange for Intermediate Traders and Investors

  • Invest in cryptocurrencies and 3,000+ other assets including stocks and precious metals.

  • 0% commission on stocks - buy in bulk or just a fraction from as little as $10. Other fees apply. For more information, visit etoro.com/trading/fees.

  • Copy top-performing traders in real time, automatically.

  • eToro USA is registered with FINRA for securities trading.

30+ million Users worldwide
Securities trading offered by eToro USA Securities, Inc. (“the BD”), member of FINRA and SIPC. Cryptocurrency offered by eToro USA LLC (“the MSB”) (NMLS: 1769299) and is not FDIC or SIPC insured. Investing involves risk, and content is provided for educational purposes only, does not imply a recommendation, and is not a guarantee of future performance. Finbold.com is not an affiliate and may be compensated if you access certain products or services offered by the MSB and/or the BD
Finbold Career

Join Finbold's newsroom, become a Sales Executive today!

Apply now to join Finbold as a crypto/finance news writer!

Latest posts

Finance Digest

By subscribing you agree with Finbold T&C’s & Privacy Policy

Related posts

Home

IMPORTANT NOTICE

Finbold is a news and information website. This Site may contain sponsored content, advertisements, and third-party materials, for which Finbold expressly disclaims any liability.

RISK WARNING: Cryptocurrencies are high-risk investments and you should not expect to be protected if something goes wrong. Don’t invest unless you’re prepared to lose all the money you invest. (Click here to learn more about cryptocurrency risks.)

By accessing this Site, you acknowledge that you understand these risks and that Finbold bears no responsibility for any losses, damages, or consequences resulting from your use of the Site or reliance on its content. Click here to learn more.