
Update addresses a flaw where malicious dApps could substitute transaction data during the signing process.
AI-generated summary
The vulnerability allowed a malicious dApp to initiate a second signing command during an active transaction review, potentially swapping the transaction data. Ledger's fix prevents new signing sessions during active reviews.
Ledger users should update the Ethereum app to version 1.22.2 after official code changes showed that a malicious dApp or other connected host could start a second signing command while a transaction was still under review.
In the path described by security company TestMachine, pressing approve could return a signature for substituted data instead of the transaction shown on the device.
TestMachine said on Aug. 22 that the attack required a dApp with WebHID access. The group said a second command could replace the transaction held in memory without opening a new review, leaving the original details on screen while the device signed the replacement.
It said the behavior was validated on Ledger Flex.
Ledger’s code history shows one official fix commit saying new signing commands could tear down an active review before returning an error. Another added state checks because approval callbacks previously signed without confirming that the app remained in the expected signing state.
Version 1.22.2 closes that documented path by refusing a new signing session during an active review and rejecting an approval callback when the state no longer matches. The reviewed sources establish a code-level fix for those entry and callback defects.
TestMachine asserted that shared code extended the issue to Nano X, Nano S Plus, Stax, and Apex, and the tagged app manifest lists those models alongside Flex as build targets.
Ledger’s release comparison starts from version 1.22.1, while the earliest affected app release remains undisclosed.
Ledger’s changelog dates 1.22.2 to Aug. 12, GitHub shows the signed tag on Aug. 13, and TestMachine said on Aug. 22 that the fix was not yet released.
Ledger CTO Charles Guillemet said on Aug. 23 that Ledger Donjon had found a bug in “certain clear signing flows” and deployed the fix about two weeks earlier. The sources leave open whether TestMachine was referring to distribution through Ledger Wallet.
Guillemet said Donjon found the bug before TestMachine contacted Ledger’s bounty program, while TestMachine said its Azimuth system found the issue and that it shared and verified the finding with Ledger.
Users should confirm that Ethereum app 1.22.2 is installed. Guillemet also advised keeping device firmware, apps, and client software current, although the public sources give no firmware minimum specific to this flaw.
They report no confirmed in-the-wild exploitation, lost funds, or private-key extraction.
AI outlook — possibilities, not facts
Users will update Ethereum app to version 1.22.2.
Likely · Within weeks

BNB Smart Chain has launched its Pasteur hard fork, an upgrade designed to improve network security, bridge verification, and block capacity. The update integrates three BNB Evolution Proposals to streamline transaction processing and validator operations.

A Zilliqa Ledger application bug exposed 6,772 accounts and enabled the theft of 683.13 million ZIL. The flaw, which caused biased signatures, allowed attackers to reconstruct private keys. Zilliqa has paused legacy transactions as users migrate to Zilliqa EVM.

The anonymous AI model 'Ox Alpha' has gained significant attention for its high performance on coding benchmarks. Despite its viral popularity and endorsement by tech leaders, the developer remains unknown, with analysts pointing toward Zhipu AI as a likely source.

Draft EIP-8390 proposes removing Ethereum's 512-validator sync committee and Altair light-client interface, replacing them with offchain zero-knowledge proofs. The change aims to reduce annual consensus issuance by 33,800 ETH but lacks a defined replacement roadmap.

The eCash Alpha-chain fork, a rehearsal for the permanent fork, successfully created a separate ECX asset for testing from Bitcoin block 963,648 on Aug. 23. The actual 1:1 ECX allocation to Bitcoin holders is now scheduled for the Mainnet launch around block 973,728 on Oct. 31, with Beta stage slated for Sept. 20.

ACE Robotics Chairman Wang Xiaogang predicts a breakthrough in embodied AI by late 2026. The startup, backed by Ant Group and SenseTime, is addressing the industry's training data shortage to transition humanoid robots from demonstrations to commercial applications.