BTC ETH SOL BNB XRP Fear & Greed
AltcoinGordon
AI

Ledger Bug: Who Disclosed It Publicly, Donjon or Outsider?

Coinfomania says Ledger's own Donjon team disclosed the Ethereum app vulnerability, while CryptoBriefing and The Cryptonomist EN say the public disclosure came from an external security researcher/firm, TestMachine.

Original AltcoinGordon illustration for: Ledger Bug: Who Disclosed It Publicly, Donjon or Outsider?
Original illustration, drawn for this story by AltcoinGordon.

Coinfomania says Ledger's own Donjon team disclosed the Ethereum app vulnerability, while CryptoBriefing and The Cryptonomist EN say the public disclosure came from an external security researcher/firm, TestMachine.

What all sources agree on

  • A race condition bug in Ledger's Ethereum app could have let a malicious dApp swap a legitimate transaction for a harmful one during signing.
  • The vulnerability was patched on August 12, 2026, shipping in Ethereum app version 1.22.2.
  • Ledger's internal security team, Donjon, discovered the flaw before any external party flagged it, using AI-assisted tools.
  • No confirmed reports of funds lost to the vulnerability had surfaced as of publication.
  • Ledger CTO Charles Guillemet commented publicly on the fix and the disclosure.

Where the reports disagree

1Who publicly disclosed the vulnerability

The issue was disclosed by Ledger Donjon, emphasizing proactive security measures.

Coinfomania

That changed between August 21 and 23, when a security researcher operating under the name TestMachine publicly disclosed the bug.

CryptoBriefing

Security firm TestMachine disclosed the bug publicly between August 21 and 23, 2026, using an AI agent called Azimuth.

The Cryptonomist EN

What would settle it: Ledger's own security advisory or TestMachine's original disclosure post identifying who published the finding and when.

What to make of it

Treat the underlying technical facts—the race condition bug, the August 12 patch in v1.22.2, and Donjon's internal discovery—as settled across all reports. The identity of who made the vulnerability public is contested and should not be repeated as fact until Ledger or TestMachine's own disclosure record is checked.

Treat the underlying technical facts—the race condition bug, the August 12 patch in v1.22.2, and Donjon's internal discovery—as settled across all reports. The identity of who made the vulnerability public is contested and should not be repeated as fact until Ledger or TestMachine's own disclosure record is checked.