Ledger Chief Technology Officer Charles Guillemet said recent market FUD targeting Ledger stems from claims by a smart contract security company that it had found a vulnerability in Ledger’s Ethereum application, even though the issue had already been fixed.
Guillemet said Ledger’s Ethereum app did previously contain a flaw related to parts of the Clear Signing flow. He said the vulnerability was discovered by Donjon, Ledger’s in-house security research team, using an AI-driven vulnerability research tool, and that the fix was completed and deployed two weeks ago. Users who promptly update their Ledger device firmware and application will be protected.
Disclosure process is at the center of the dispute
According to Guillemet, the security company contacted Ledger’s bug bounty program only after Ledger had already completed the fix. He said the firm did not follow a responsible disclosure process and did not communicate with the bug bounty team, but later published material that implied the issue remained unresolved.
He said that approach was not genuine security research, but an attempt to create panic and attract attention.
Ledger’s view on AI and security research
Guillemet said AI is changing the cybersecurity field, with both attackers and defenders able to use it to improve efficiency. He added that AI-driven security research can raise security across the ecosystem only when it follows basic principles such as responsible disclosure and verification before publication.
Users are being told to keep software updated
Guillemet’s final message to Ledger users was to keep device firmware, the Ledger app, and related software on the latest versions. He said doing so will automatically give users access to the latest security fixes and research results, and that users do not need to be swayed by the current FUD as long as they update software in time and maintain sound security habits.

