TestMachine’s Azimuth agent scanned Ledger’s Ethereum app. It found a transaction replacement vulnerability. The CTO called it fear-mongering.
I’ve seen this playbook before. In 2017, I spent 40 hours auditing a PotCoin ICO contract. Found an integer overflow. The team called it impossible. Then they paid the bounty. Ledgers do not lie, only the auditors do.
Ledger shipped 7 million devices. They dominate the hardware wallet market. Their Ethereum app shares the same APDU/UI code across Nano X, Nano S Plus, Stax, and Apex. The bug? A malicious site can inject a second command while the user reviews the first. The APDU channel stays open. The user sees a small transfer but signs an infinite token approval.
This is not a theoretical risk. This is a real attack vector that undermines “clear signing” – the entire trust model of hardware wallets. The fix came in version 1.22.2. The commit message: one line – “Security issues”. No public advisory. No CVE. No coordination with users.
Here is the core: TestMachine’s AI agent Azimuth claims 86.3% detection on known vulnerabilities in EVMBench with 2.7% false positives. I have audited enough smart contracts to know that benchmark numbers are best-case. The real world adds noise. But the finding itself is valid. The vulnerability is real. The attack works. The code does not lie.
The fix is correct, but the process is broken. A single line commit message is not a security disclosure. It is a cover-up. Ledger’s internal Donjon team also found the bug using ML. Both sides found it. The difference is transparency. One side published research. The other side pushed a silent patch and called the researcher a fear-monger.
Contrarian angle: The real story is not about Ledger’s incompetence. It is about the speed of AI security research outpacing human coordination. Ledger’s CTO, Guillemet, said the disclosure was “fear-mongering.” He is wrong. But TestMachine is also not blameless. They skipped coordinated disclosure. They published before users had a chance to update. The industry needs a new standard: AI-discovered vulnerabilities require faster disclosure windows, but also require responsible timing.
The market impact is limited. Ledger has 7 million devices. Users are sticky. But the trust tax is real. Beta is the tax you pay for ignorance. Users who ignore the update are paying beta. The Trezor alternative – open-source, more transparent – may see a small inflow. But the bigger shift is in the security audit industry. AI agents like Azimuth will become standard. Sanity checks before sanity wins.
Takeaway: Update your Ledger to 1.22.2. But more importantly, understand that the era of trusting the hardware screen is over. The only truth is the code. And the code is now being audited by machines that do not sleep. The algorithm executes, but the human decides. Decide to update.