Ledger has released a critical security update for its Ethereum application, urging all users to upgrade to version 1.22.2 immediately. The patch addresses a significant vulnerability that could allow a malicious decentralized application (dApp) or compromised host to substitute transaction data during the signing process, potentially causing users to approve unintended transactions.
Security researchers at TestMachine disclosed that the vulnerability exploited a race condition in the signing workflow. When a transaction remained under review on the Ledger device, a malicious dApp with WebHID access could initiate a second signing command. This secondary command could replace the original transaction held in memory without triggering a new review screen, leaving the user-facing display unchanged while the device actually signed the substituted data.
The attack methodology was successfully validated on the Ledger Flex hardware wallet, though researchers indicate the underlying vulnerability affected multiple Ledger device models, including the Nano X, Nano S Plus, Stax, and Apex.
Ledger’s official code repository reveals two key fixes implemented in version 1.22.2. The first addresses new signing commands that could prematurely terminate an active review before returning an error. The second introduces state validation checks to ensure approval callbacks cannot execute without confirming the application remains in the expected signing state. The updated version prevents new signing sessions during active reviews and rejects approval callbacks when state conditions are not met.

Ledger Chief Technology Officer Charles Guillemet confirmed that Ledger’s internal security team, Donjon, discovered the vulnerability in certain clear signing flows and deployed the fix approximately two weeks prior to public disclosure. Guillemet noted that the bug was identified before TestMachine’s bounty program submission, though TestMachine claims its Azimuth detection system independently discovered and verified the issue.
Users are strongly advised to verify their Ethereum application version and update to 1.22.2 as soon as possible. Security best practices recommend maintaining current device firmware, application versions, and client software. At present, there are no confirmed reports of in-the-wild exploitation, stolen funds, or private key compromise resulting from this vulnerability.
The issue is distinct from previous Ledger security incidents, including the native Zilliqa application flaw involving Schnorr nonce leakage and the 2023 Connect Kit compromise that involved a malicious JavaScript library.
Also Read
- WTI Crude Oil Falls Below $84 as Dollar Strengthens, but Iran Tensions Cap Losses
- Euro Slides Further as Dollar Gains Momentum Ahead of PCE Data and Jackson Hole
- EUR/JPY Climbs Toward 186.00 Following Support Test at Channel Floor
- EIP-8390 Proposal Seeks to Cut 33,800 ETH Consensus Issuance, Replacing Altair Light Clients with Offchain ZK Proofs

