AI Firm Exposes Ledger Bug, CTO Calls It Fear-Mongering After Quiet Fix
An synthetic intelligence (AI) safety agency went public with a Ledger Ethereum app bug. Ledger says it had already mounted the flaw quietly, two weeks earlier.
Chief know-how officer Charles Guillemet known as the disclosure fear-mongering. The patch shipped on August 12 with a one-line observe and no safety bulletin.
What the Ledger Ethereum App Bug Actually Did
Ledger sells one core promise. The display screen reveals you what you might be signing. That promise has a reputation. Ledger calls it clear signing, and it turns uncooked transaction code into plain phrases on the gadget display screen.
TestMachine says it discovered a manner round that. The agency builds an AI agent known as Azimuth that hunts exploits in sensible contracts. On its personal EVMBench benchmark, Azimuth catches 86.3% of identified bugs with roughly 2.7% false positives.
Here is the flaw in plain phrases. A malicious web site might ship the gadget a second command when you have been nonetheless studying the primary one.
The channel between browser and gadget is named the Application Protocol Data Unit, or APDU. It stored listening throughout the overview. So it accepted the swap.
You would learn a small switch on display screen. Then you’ll faucet approve. And you’ll really signal a limiteless token approval to a stranger.
That final half is why this issues. Chainalysis has traced roughly $1 billion in crypto stolen via approval phishing since May 2021. Those victims signed the approvals themselves.
TestMachine says it confirmed the bug on a Ledger Flex. Ledger has bought greater than 7 million gadgets throughout 180 nations.
Ledger’s Donjon Team Says It Got There First
Guillemet flips the timeline. Donjon is Ledger’s in-house hacking crew. He says it caught the bug with its personal AI instruments and shipped the repair first.
The public changelog backs the date. Version 1.22.2 landed on Aug. 12. Its total safety observe says “Security points.”
Donjon has revealed 22 numbered safety bulletins. None of them covers this bug. The newest, dated June 4, offers with a Monero key-recovery challenge as a substitute.
That silence is the hole TestMachine walked into. Ledger closed the opening, then by no means informed house owners what it had closed.
Guillemet’s sharper criticism is about manners. He says TestMachine contacted the bounty program solely after the patch shipped. It by no means spoke with the bounty crew.
“…Then they revealed a thread implying the issue is unsolved. It just isn’t. That’s not safety analysis. That’s manufacturing concern for consideration,” Charles Guillemet, Ledger CTO remarked.
Follow us on X to get the newest information because it occurs
TestMachine praised the pace of the repair and turned down the reward. Ledger pays bounties in Bitcoin, at an quantity it units case by case.
AI Found the Bug Twice, But Humans Still Fought
Both sides used machine studying to succeed in the identical defect. That is the half value watching.
Ledger has made this argument earlier than. Its executives have mentioned for months that AI attackers threaten wallets greater than weak {hardware} does.
Guillemet drew his line at self-discipline.
“AI-speed analysis solely makes the ecosystem safer if the folks doing it nonetheless comply with fundamental safety ideas. Disclose responsibly. Verify earlier than you publish. Don’t confuse noise with a discovering.”
The battle itself is acquainted. Security corporations have gone loud after hacking a Trezor device, and CertiK researchers fought Kraken over disclosure phrases in 2024.
So is the flaw. Back in January 2021, Donjon disclosed that this identical Ethereum app failed to point out transaction knowledge for unsupported belongings. Same app, identical lesson. What you noticed was not what you signed.
AI now surfaces these bugs in hours. Vendors and researchers nonetheless coordinate at human pace. That hole is the place this argument lives.
For house owners, the repair is uninteresting. Open Ledger Live, replace the Ethereum app, and examine that it reads 1.22.2.
The put up AI Firm Exposes Ledger Bug, CTO Calls It Fear-Mongering After Quiet Fix appeared first on BeInCrypto.
