Ledger Bug Exposed: AI Firm vs. CTO's "Fear-Mongering" Claim
Summary
An artificial intelligence security firm has exposed a bug in Ledger's Ethereum app, which Ledger says it quietly fixed two weeks earlier. The bug allowed a malicious website to trick users into approving unlimited token transfers. Here's the thing: Ledger's core promise is "clear signing," where the device screen shows exactly what you are signing. TestMachine, the AI firm, found a way around this. A second command could be sent to the device while a user was still reviewing the first one. This meant you could read a small transfer on screen, approve it, and unknowingly sign an unlimited token approval to a stranger. What's interesting is that Ledger's CTO, Charles Guillemet, called the disclosure "fear-mongering." He states Ledger's in-house hacking team, Donjon, found and fixed the bug first, shipping a patch on August 12. However, this fix was noted with only a one-line changelog entry and no security bulletin. TestMachine confirmed the bug on a Ledger Flex device. The bottom line: This matters because Chainalysis reports roughly $1 billion in crypto has been stolen through approval phishing since May 2021, with victims signing the approvals themselves.
This is an AI-generated audio summary. Always check the original source for complete reporting.