Ledger Patches Ethereum App Flaw That Could Have Let Attackers Swap Transactions
Hardware wallet maker Ledger has confirmed and patched a vulnerability in its Ethereum app that could have let attackers exploit a timing flaw, known as a race condition, to swap out a transaction before it was signed. This could potentially have redirected funds to an attacker-controlled address without the user's knowledge.
The issue affected version 1.22.1 of the Ethereum app. Ledger released a fix in version 1.22.2 on August 13, 2026, and further hardened its systems with an updated Secure SDK (version 26.6.1) on August 21, 2026. The company has denied claims that its systems were breached, framing the incident as a responsibly disclosed and patched vulnerability rather than an active hack.
While hardware wallets are designed to be a more secure alternative to storing cryptocurrency on exchanges, this incident is a reminder that even trusted security hardware relies on software that can contain flaws. Users who rely on Ledger devices for managing cryptocurrency, including small businesses holding digital assets, should ensure their apps and firmware are kept current to benefit from security patches as soon as they're released.