The error was discovered by the Ledger Donjon team using an AI-powered vulnerability detection system, according to a senior executive. The issue affected the transparent signature feature, which is designed to display transaction details—such as the amount, address, and smart contract actions—on the screen before the user confirms them.
Ledger deployed the patch approximately two weeks before it became publicly known. Developers assured users that those with updated firmware and apps are protected. As of August 24, no confirmed cases of theft related to this vulnerability have been reported.
Researchers at TestMachine, using the AI tool Azimuth, reported that attackers could replace transaction data and send a competing, desired command at the moment when the Ledger user is still reviewing the original transaction. As a result, the device could display one transaction while signing another. TestMachine stated that the vulnerability affects several hardware wallet models, including the Nano X, Nano S Plus, Stax, and Apex.
Ledger itself has not published a detailed technical description of the vulnerability or a list of affected wallet versions. Ledger’s CTO stated that TestMachine contacted Ledger only after the company had released the fix. He called TestMachine’s claim about the issue’s relevance “fearmongering to attract attention.” In turn
TestMachine analysts stated that they shared their research findings with Ledger and declined the reward.
Every Ledger running the Ethereum app is vulnerable to signature substitution
A malicious dApp with WebHID access could race an APDU during your transaction review and swap the transaction being signed while the device still displays the original.
Here's what you need to know: pic.twitter.com/uWk2KvqVwq
— TestMachine (@testmachine_ai) August 22, 2026Ledger representatives recommend wallet owners to update the Ledger Wallet software, device firmware, and the installed Ethereum application. Updating only the desktop or mobile interface may not be sufficient if the application on the device itself is outdated. Users should verify transaction details directly on the device’s secure screen. Blind signing can be dangerous, as the device does not always display every smart contract action in a readable format, Ledger experts warned.
Previously anonymous blockchain researcher ZachXBT suggested followers to stop using Ledger hardware wallets. The blockchain investigator fears that too-frequent updates change the interface and sometimes disrupt the device’s basic functions.

