Ledger Fixed Clear-Signing Bug in Ethereum App; Exploitation Not Confirmed
Ledger’s security bulletin warns of a bug in the Ethereum app versions 1.19.0 through 1.22.2. A fix is available in version 1.22.3.

A clear-signing bug in the Ethereum app could, under specific circumstances, display only one operation on the hardware wallet’s screen even though the user was signing an entire bundle of transaction operations. Ledger disclosed the vulnerability in Ledger Security Bulletin 024 on August 27, 2026. The fix is included in Ethereum app version 1.22.3.
According to Ledger, the issue affects Ethereum app versions 1.19.0 through 1.22.2. Users should install version 1.22.3 or later and verify the version number directly on the device.
The Ethereum app clear-signing bug affected fields with more than 255 operations
The bug was located in the clear-signing mechanism, which displays transaction data on the device before the signature is confirmed. For a field containing more than 255 operations, the app could display only one operation. The signature itself, however, authorized the entire bundle.
The hardware wallet’s display is intended to give users an independent way to check what they are signing, even when the transaction is prepared by a computer or another connected interface. The described bug could bypass this check for the specified type of input.
Ledger also states that exploitation requires a combination of additional conditions. An attacker would need a compromised host computer or interface and a clear-signing descriptor working with a field controlled by the attacker that contains more than 255 items.
Laboratory proof of concept without moving real funds
Ledger Donjon’s security team validated an end-to-end proof of concept on a private fork of the network. According to the bulletin, the transaction was not sent to the public network and no real funds were moved.
Ledger writes that it has no evidence of exploitation against users. This does not constitute independent evidence that no production incident occurred, but the bulletin describes only laboratory validation, not a confirmed theft or hack of the company.
Public discussion also touched on OneKey’s claim about a separate race-condition issue in version 1.22.1. This technical description has not been independently confirmed by a primary source verified for bulletin LSB 024. It is likewise incorrect to attribute the fix for the LSB 024 bug to version 1.22.2: Ledger’s timeline states that 1.22.2 was released without this fix and that the first fixed version was 1.22.3, released on August 25.
What Ethereum app users should do
- Update the Ethereum app to version 1.22.3 or later.
- Verify the installed version number directly on the hardware device.
- Continue checking the data displayed on the wallet screen when signing.
Further developments will depend on whether Ledger or independent security researchers publish details about the claimed OneKey test and its possible relationship to LSB 024. It will also be important whether evidence of exploitation outside the laboratory or additional advisories concerning clear-signing in the Ethereum app emerge.
Sources
- Ledger Donjon — Ledger Security Bulletin 024 – Confirms the bug mechanism, the range of affected versions 1.19.0 through 1.22.2, the release of fix 1.22.3 on August 25, the exploitation conditions, and the laboratory nature of the proof of concept.
- Decrypt – Documents the public discussion following OneKey’s claim and the recommendation to update the Ethereum app to at least 1.22.3; however, its claim about a fix in 1.22.2 does not correspond to the primary bulletin for the specific LSB 024 bug.
Verified and updated: 08/27/2026 20:34



