Skip to content
Active Currencies: 18,656
Market Cap: $2.657T
Bitcoin Dominance: 59.39%
24h Market Cap Change: $-0.96

Ledger pushes back on Ethereum app flaw claims: ‘Manufacturing fear for attention’

On what grounds did Ledger accuse TestMachine of irresponsible disclosure?

Ledger pushes back on Ethereum app flaw claims: 'Manufacturing fear for attention'

The Ledger Ethereum [ETH] app has caught the spotlight, but not for good reasons. According to Ledger’s CTO Charles Guillemet, there has been a vulnerability in the app, which has been pushed by a “smart contract security” company and concerns the Ledger signers.

However, Guillemet took to X on the 23rd of August and clarified that the issue “was fixed and deployed two weeks ago.”

Though the vulnerability was fixed in Ethereum app version 1.22.2 on the 12th of August, the controversy arose because Ledger did not publicly explain the vulnerability when it released the patch.

Ledger vs. TestMachine

The controversy revolved around a security flaw that caused the user to sign something different from what they saw on Ledger’s screen.

That is particularly serious because the main security advantage of a hardware wallet is that the device itself allows users to verify the transaction before approving it.

A security researcher called TestMachine later disclosed the issue publicly. This is what led to a dispute between the researcher and Ledger over whether the disclosure was responsible or unnecessarily alarming.

Now, since Ledger had already discovered the issue using Ledger’s Donjon security team and AI-powered tools, Guillemet took to X and clarified,

This company [TestMachine] reached out to our bounty program after the fix was already shipped, and did not follow responsible disclosure, they actually never discussed with the bounty program team.

He added,

Then they published a thread implying the problem is unsolved. It is not. That’s not security research. That’s manufacturing fear for attention.

What’s more?

This is where ERC-7730 comes into the picture, which aims to improve how transaction information is displayed and verified on wallets. Fortunately, there are no reported cases of funds being stolen through this specific vulnerability.

However, users are advised to update their Ledger firmware and Ethereum app and continue verifying transactions on the device before signing.

This comes on the heels of the Coldcard exploit, wherein Ledger also gained attention. However, Ledger clarified that the Coldcard vulnerability was specific to Coldcard’s firmware and did not compromise Ledger’s Bitcoin hardware wallets.


Final Summary

  • The controversy was mainly FUD, which revolved around a security flaw in Ledger’s Ethereum app.
  • Ledger had already discovered the issue before the outside company publicly disclosed it.
Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Ishika Kumari

Journalist

Ishika Kumari is a Crypto Analyst at AMBCrypto, specializing in regulatory developments, market dynamics, and blockchain’s real-world impact. She breaks down complex protocols and legislation into practical, easy-to-understand insights.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.