TestMachine discloses Ledger Ethereum app flaw as Ledger says the issue was already fixed

TestMachine discloses Ledger Ethereum app flaw as Ledger says the issue was already fixed

N
News Editor
2026-08-23 22:23:18
AI security firm TestMachine has publicly disclosed a vulnerability in Ledger’s Ethereum application, saying a malicious website could send a second transaction request to a hardware wallet while a user is reviewing the first one. According to TestMachine, that flow could lead a user to unknowingly sign an unlimited token approval. The company said the issue was discovered by its autonomous AI agent, Azimuth, and verified on a Ledger Flex device. Ledger pushed back on the disclosure timeline. Chief Technology Officer Charles Guillemet said the company’s internal security team, Donjon, had already found and fixed the flaw on Aug. 12 using its own AI tools, though the related update included only a one-line note. He argued that TestMachine contacted Ledger’s bug bounty program only after the patch had been released and then made the matter public, calling the move an attempt to create panic and draw attention. TestMachine, for its part, praised Ledger’s speed in fixing the issue and said it declined the bounty reward.

AI security company TestMachine has publicly disclosed a vulnerability in Ledger’s Ethereum application. The firm said a malicious website could send a second transaction instruction to a user’s hardware wallet while the user is reviewing the first transaction, creating a scenario in which the user could unknowingly sign an unlimited token approval.

TestMachine said the flaw was discovered through autonomous scanning by its AI agent Azimuth and was verified on a Ledger Flex device.

Ledger says its team had already found and patched the flaw

Ledger Chief Technology Officer Charles Guillemet said the company’s internal security team, Donjon, had identified and fixed the vulnerability before TestMachine’s disclosure. He said the issue was found and patched on Aug. 12 with the help of Ledger’s own AI tools, although the update released at the time contained only a one-line explanation.

Guillemet said TestMachine contacted Ledger’s bug bounty program only after the patch had already been published and then went public with the matter. He described that sequence as 「creating panic to gain attention.」

TestMachine says it praised the fix and declined the bounty

TestMachine said it commended Ledger for the speed of the fix and declined to accept a bug bounty reward.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
80

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.