Ledger fixes vulnerability in Ethereum app, dismisses FUD
Ledger fixed a vulnerability in the Ethereum app before an external security company went public with the issue. Charles Guillemet, chief technology officer of Ledger, responds to reports suggesting the problem still exists. According to him, that is not correct: the error was found and resolved by Ledger’s internal team two weeks ago. Users who keep their apps up to date are protected.
Ethereum is available at OKX and Bybit.
In short:
- A vulnerability in certain signing flows of the Ledger Ethereum app was discovered and fixed by the internal Donjon team two weeks ago.
- An external security company only reported the vulnerability after the fix had already been rolled out, and subsequently published messages giving the impression that the problem was still unresolved.
- Ledger CTO Guillemet urges users to keep their firmware and apps up to date and to ignore the FUD.
Vulnerability patched two weeks ago
The vulnerability was located in certain clear signing flows of the Ledger Ethereum app. Ledger’s internal research team, Donjon, discovered the issue through its own AI-driven research environment. The fix was rolled out two weeks ago.
Guillemet states that users who keep their Ledger firmware and apps up to date automatically benefit from the latest security improvements and have nothing to fear.
External company acted only after the solution
A company that describes itself as a smart contract security specialist only contacted Ledger’s bug bounty programme after the fix had already been rolled out. Moreover, according to Guillemet, the company never held a substantive conversation with the bounty team.
Afterwards, the company published messages that gave the impression that the vulnerability had not yet been resolved. Guillemet rejects that framing, describing it as deliberately creating unrest for attention rather than serious security research.
AI is changing the security landscape
Guillemet acknowledges that AI is changing the work of both attackers and defenders. He states that Donjon actively uses AI to find vulnerabilities before users are affected. In his view, that is the right approach.
At the same time, he warns that speed without responsible disclosure actually harms the ecosystem. According to him, a party that publishes findings without verification and without consultation with the party involved contributes negatively on balance, regardless of the technology used. Ethereum currently stands at $2.450, an increase of 1.5% in the past 24 hours. Analyst Michaël van de Poppe previously wrote about a possible price movement towards the highs.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.