A critical security vulnerability in Ledger's Ethereum app could allow malicious dApps to substitute transactions during signing, undermining user trust in hardware wallet security
Early and rising — still a small slice of coverage but gaining +2pp over the last 3 days. This is where attention may be headed next.
A critical vulnerability was discovered in Ledger's Ethereum app that could allow malicious decentralized applications to substitute transactions during the signing process, potentially enabling unauthorized fund transfers. This represents the second severe vulnerability reported in Ledger's ecosystem in 2026, raising questions about the security rigor of widely-used hardware wallet infrastructure.
Hardware wallet security breaches undermine the foundational trust assumption that enables retail participation in crypto markets; when users lose confidence in the security of their custody solutions, they reduce exposure or exit the market entirely. Repeated security issues in dominant wallet providers can create broader sentiment damage that affects asset valuations independent of the specific vulnerability's technical scope.
Still mostly niche and specialist coverage — not yet picked up broadly by mainstream press.
"So far in 2026, the Ledger team has reported two more severe vulnerabilities... a more serious bug in Ledger's Zilliqa app, which had existed since 2019, exposed private keys through flawed random number generation and led to the theft of 683 million ZIL from over 6,700 accounts."
"A critical vulnerability that could have allowed hackers to drain a crypto wallet during a single transaction in Ledger's Ethereum app has been flagged as of August 26... this bug allowed malicious decentralized applications (DApps) to swap a harmless transfer for an unlimited token approval, granting backdoor access to all ERC-20 tokens on users' Ledger hardware wallets."
"a malicious dApp or other connected host could start a second signing command while a transaction was still under review. In the path described by security company TestMachine, pressing approve could return a signature for substituted data instead of the transaction shown on the device."