The dispute centers on whether the vulnerability remained an active threat. TestMachine, utilizing its Azimuth AI research tool, reported that a malicious application could potentially swap transaction data while a user reviewed their Ledger screen. The firm identified the issue across several models, including the Flex, Nano X, Nano S Plus, Stax, and Apex. Ledger acknowledged a bug existed in specific clear signing flows but maintains that updated firmware and application versions effectively neutralize the threat.
Guillemet criticized the disclosure, labeling the firm’s public warnings as an attempt to generate alarm. He stated that Ledger’s internal security research team, Ledger Donjon, had already identified and resolved the issue using their own AI systems prior to the firm’s contact with the company’s bounty program. Despite the public back-and-forth, no confirmed reports of stolen funds linked to this specific flaw had surfaced by August 24, 2026.

Comments (0)
No comments yet. Be the first!