Ledger pushes back on Ethereum app flaw claims: ‘Manufacturing fear for attention’

The Ledger Ethereum [ETH] app has caught the highlight, however not for good causes. In keeping with Ledger’s CTO Charles Guillemet, there was a vulnerability within the app, which has been pushed by a “sensible contract safety” firm and considerations the Ledger signers.
Nonetheless, Guillemet took to X on the twenty third of August and clarified that the problem “was fastened and deployed two weeks in the past.”
Although the vulnerability was fastened in Ethereum app model 1.22.2 on the twelfth of August, the controversy arose as a result of Ledger didn’t publicly clarify the vulnerability when it launched the patch.
Ledger vs. TestMachine
The controversy revolved round a safety flaw that brought about the person to signal one thing totally different from what they noticed on Ledger’s display screen.
That’s notably severe as a result of the principle safety benefit of a {hardware} pockets is that the gadget itself permits customers to confirm the transaction earlier than approving it.
A safety researcher referred to as TestMachine later disclosed the problem publicly. That is what led to a dispute between the researcher and Ledger over whether or not the disclosure was accountable or unnecessarily alarming.
Now, since Ledger had already found the problem utilizing Ledger’s Donjon safety group and AI-powered instruments, Guillemet took to X and clarified,
This firm [TestMachine] reached out to our bounty program after the repair was already shipped, and didn’t comply with accountable disclosure, they really by no means mentioned with the bounty program group.
He added,
Then they printed a thread implying the issue is unsolved. It isn’t. That’s not safety analysis. That’s manufacturing concern for consideration.
What’s extra?
That is the place ERC-7730 comes into the image, which goals to enhance how transaction data is displayed and verified on wallets. Thankfully, there are not any reported circumstances of funds being stolen via this particular vulnerability.
Nonetheless, customers are suggested to replace their Ledger firmware and Ethereum app and proceed verifying transactions on the gadget earlier than signing.
This comes on the heels of the Coldcard exploit, whereby Ledger additionally gained consideration. Nonetheless, Ledger clarified that the Coldcard vulnerability was particular to Coldcard’s firmware and didn’t compromise Ledger’s Bitcoin {hardware} wallets.
Closing Abstract
- The controversy was primarily FUD, which revolved round a safety flaw in Ledger’s Ethereum app.
- Ledger had already found the problem earlier than the skin firm publicly disclosed it.





