Ledger CTO Charles Guillemet confirmed that a vulnerability in certain clear-signing flows of the Ledger Ethereum app was discovered and fixed two weeks ago, with users on current firmware protected from the issue.

The vulnerability was discovered internally by Ledger Donjon, the company's security research division, and patched on August 12. A third-party firm that describes itself as a smart contract security vendor disclosed the issue publicly on August 22, ten days after the fix was already deployed to users. Guillemet said in his post on X that the disclosing firm implied the vulnerability remained unresolved at the time of its announcement.

Current total value locked, last 90 days
Current total value locked, last 90 days · MSB Intel data desk

Ledger hardware wallets rely on firmware and app updates to protect against signing attacks, in which a malicious interface could trick a user into authorizing a transaction they did not intend. The Ethereum app running on Ledger devices handles the display and approval of transaction data before signing. Clear-signing flows, which show users the full contents of a transaction rather than a summary, are a security control designed to prevent such attacks.

The company did not disclose the specific attack vector the vulnerability enabled or name the firm that disclosed it. Guillemet's statement focused on the timeline: internal discovery, rapid patching, and external disclosure after the fix shipped.

Ledger has roughly 6 million active hardware wallet users. The company ships security updates through its Ledger Live desktop and mobile applications, which users must manually install or enable auto-update to receive. The claim that current firmware protects against the issue assumes users have updated since August 12.

The disclosure sequence mirrors a broader tension in crypto security between companies that discover and patch vulnerabilities internally and researchers who disclose findings in real time. Ledger's two-week window between patch and public disclosure is longer than many software vendors' standard 90-day coordinated disclosure period, though the company prioritizes shipped protection over advance warning.

The number that decides whether this becomes a material risk issue for Ledger users is the adoption rate of the August 12 patch: if fewer than half of active Ledger Ethereum app users have updated since that date, a significant portion would remain exposed until they manually install the new firmware.