Is Ledger safe? The question spiked in the last week of August 2026 because two companies gave the public two different answers about the same bug. A security firm called TestMachine said every Ledger device running the Ethereum app could be talked into signing a transaction its screen never displayed. Ledger's chief technology officer replied that his own team had found the flaw, patched it, and shipped the fix before anyone outside the company wrote a word about it. Both of those statements hold up, and the gap between them is the part worth reading.
What the Ledger Ethereum app bug did
Every hardware wallet rests on one promise: the screen shows you what you are about to approve, and the chip approves nothing else. This bug broke the second half of that promise inside certain clear signing flows, the flows meant to render a transaction in plain language instead of a wall of hex.
Communication between a computer and a Ledger device travels in a command format called APDU. In TestMachine's public thread, a malicious site with browser device access could race a second command into the wallet while the first transaction was still sitting on screen awaiting your review, so the details you read and the details you authorized could come apart. You would check a small transfer to an address you recognize, press the button, and sign something you never saw.
TestMachine named the Nano X, Nano S Plus, Stax, Flex and Apex as sharing the command and interface code involved, and it stopped short of publishing a complete working proof of concept. As of 24 August 2026, no verified thefts have been traced to this weakness.
The patch arrived before the warning
Ledger shipped Ethereum app version 1.22.2 on 12 August 2026, and the release note covering it said two words: "Security issues." The update stops the device from accepting a competing signing command while a review is already open, which closes the race.
Ten days later TestMachine went public, and Ledger's chief technology officer Charles Guillemet answered on the same platform. His account is that the Donjon, Ledger's in-house security lab, found the bug with an AI-powered vulnerability research suite, and that "it was fixed and deployed two weeks ago." On the timing of the disclosure he was blunt: "That's not security research. That's manufacturing fear for attention."
TestMachine reproduced the issue on hardware and, by Ledger's account, approached the bug bounty program only after the patch had already gone out. The counter-argument is that a changelog reading "Security issues" tells an owner nothing, and an update nobody understands is an update plenty of people postpone.
So is Ledger safe today
If your Ethereum app sits at version 1.22.2 or later, this particular hole is closed, and Guillemet's position is that users who keep their apps current are protected. Open Ledger Live, update the firmware and the Ethereum app together, and check the version number rather than assuming the update ran.
That covers the immediate question. The wider one, whether a device you cannot inspect deserves your savings, is the reason this story travelled beyond the usual security accounts.
What the argument exposes about hardware wallets
Nobody reading this can verify the claim at the centre of it. You cannot open the secure element, you cannot read the code running inside the Ethereum app, and you cannot confirm from the outside whether the race condition is gone. What you can do is watch how a company behaves when something goes wrong, which is why a two-word changelog is a poor look even when the engineering underneath it was quick and correct.
Open source is not the escape hatch it sounds like either. Coldcard publishes its firmware, and a build configuration mistake from March 2021 still collapsed the randomness behind newly generated wallets, letting attackers rebuild seeds offline and drain more than 115 million USD in confirmed losses through mid-August 2026. Published code helps when somebody reads it. For four years, nobody did.
The AI detail is the piece that will keep mattering. Ledger's lab found this bug with machine assistance and TestMachine reproduced it the same way, so the cycle of discovery has compressed for defenders and attackers together, and the window between a quiet patch and a public write-up is going to keep shrinking.
Where recovery fits, and why we split it
A firmware patch answers one category of question: whether the thing in your hand does what its screen says. It leaves the other category untouched, which is what happens when the device is lost, stolen, destroyed, or when somebody talks you into reading your backup words out loud. On most wallets that answer is a single seed phrase, written once, stored somewhere, and capable of restoring everything to anyone who finds it.
We built TapSafe Recovery so no single object carries the whole answer. Your Recovery Tag holds 50 percent, your paired phone holds the other 50 percent stored encrypted in your own iCloud or Google Drive rather than on the handset, and optional Recovery Contacts hold 25 percent each while learning nothing about your holdings. Tag plus phone restores the wallet; either one alone restores nothing. The seed phrase stays available on the device as a last resort under the BIP-39 standard, so you are never tied to our hardware.
What to do this week
- Update Ledger Live, your device firmware, and the Ethereum app, then confirm the app reads 1.22.2 or higher.
- Read the destination address and the amount on the device screen every time, including for small transactions where the habit is easiest to drop.
- Revoke browser permissions for sites you no longer use, since this attack needed a page connected to your wallet to have any path at all.
- Treat any message about this bug that asks for your recovery words as a scam. Ledger will never ask, and neither will we.
- Ask where a complete copy of your recovery lives right now, and how many separate places somebody would have to reach to assemble one.
The wallet you can check
Ledger handled the engineering well and the communication badly, and that combination is common enough that it should shape how you choose hardware rather than which brand you avoid. Look for a device that renders every transaction in full before you approve it, a chip whose certification you can look up, and an audit somebody outside the company signed their name to.
The Ryder One generates keys inside an EAL6+ certified Infineon SLC38 secure element that they never leave, and the firmware was independently audited by Halborn with the full report published rather than summarized. Every transaction renders on the 1.6-inch AMOLED touchscreen before you approve it, and the button that triggers a signature is wired directly to the secure element, so no software path can sign without it. Communication runs over NFC and nothing else, which means there is no wired data channel and no Bluetooth radio to race a command down. Setup takes about 60 seconds, and the Starter Combo is 149 USD.
Update your Ledger today, and then ask what your next wallet should have to prove to you before it holds anything worth losing. See the Ryder One.
Meta description: Is Ledger safe? The Ethereum app clear signing bug was patched in 1.22.2 on 12 August 2026, ten days before it went public. What happened and what to do.




Share: