Case · DiggingBeagle record

Ledger fixed Ethereum signing-flow flaws found during internal automated/AI-assisted review

Ledger disclosed multiple Ethereum-app signing-flow vulnerabilities found through internal continuous and automated security review. One command-interleaving bug could desynchronize what the user reviewed from what was signed; another swap-path flaw could substitute a token approval for the intended payment. Ledger reported no known exploitation against users and released application/SDK fixes in August 2026.

First seen
Aug 22, 2026
Case kind
vulnerability
AI role
WITH AI
Claims
8

Reconstruction

Claims & evidence

reported findingsupported

Ledger's public Cerberus material describes a six-agent AI security harness used for iterative vulnerability discovery, proof and patching, but the security bulletins themselves characterize these findings as internal continuous/automated review rather than attributing every step to autonomous AI.

  • supports
    Ledger - Meet Cerberus AI security harness

    Locator: SRC-LEDGER-CERBERUS-SEP04

    Ledger's public Cerberus material describes a six-agent AI security harness used for iterative vulnerability discovery, proof and patching, but the security bulletins themselves characterize these findings as internal continuous/automated review rather than attributing every step to autonomous AI.
reported findingsupported

Ledger LSB-025 documents a separate swap-flow issue in which a token approval could be accepted in place of the intended payment.

  • supports
    Ledger Security Bulletin 025

    Locator: SRC-LEDGER-LSB025

    Ledger LSB-025 documents a separate swap-flow issue in which a token approval could be accepted in place of the intended payment.
reported findingsupported

For the swap flaw, exploitation required control of the transaction submitted during a swap; the beneficiary and quantity remained constrained to the already accepted swap parameters, and a separate later transaction was required to move funds.

  • supports
    Ledger Security Bulletin 025

    Locator: SRC-LEDGER-LSB025

    For the swap flaw, exploitation required control of the transaction submitted during a swap; the beneficiary and quantity remained constrained to the already accepted swap parameters, and a separate later transaction was required to move funds.
reported findingsupported

The swap-path approval/payment confusion was fixed in Ethereum app 1.22.3, published August 25, after internal automated review identified the missing operation-type check on April 28.

  • supports
    Ledger Security Bulletin 025

    Locator: SRC-LEDGER-LSB025

    The swap-path approval/payment confusion was fixed in Ethereum app 1.22.3, published August 25, after internal automated review identified the missing operation-type check on April 28.
reported findingsupported

Ledger says application-level guards for the command-interleaving class appeared in Ethereum app 1.22.2 on August 13, with SDK-level correction in Secure SDK v26.6.1 on August 21.

  • supports
    Ledger Security Bulletin 023

    Locator: SRC-LEDGER-LSB023

    Ledger says application-level guards for the command-interleaving class appeared in Ethereum app 1.22.2 on August 13, with SDK-level correction in Secure SDK v26.6.1 on August 21.
reported findingcontested

Ledger reports no known exploitation against users for the disclosed command-interleaving issue.

  • supports
    Ledger Security Bulletin 023

    Locator: SRC-LEDGER-LSB023

    Ledger reports no known exploitation against users for the disclosed command-interleaving issue.
reported findingsupported

Ledger LSB-023 documents a command-interleaving condition where displayed and ultimately signed parameters could diverge.

  • supports
    Ledger Security Bulletin 023

    Locator: SRC-LEDGER-LSB023

    Ledger LSB-023 documents a command-interleaving condition where displayed and ultimately signed parameters could diverge.
reported findingsupported

Ledger states it has no evidence that the disclosed Ethereum signing issues were exploited against users.

  • supports
    Ledger Security Bulletin 025

    Locator: SRC-LEDGER-LSB025

    Ledger states it has no evidence that the disclosed Ethereum signing issues were exploited against users.

Implications

What remains unknown

  • Public materials do not provide a step-by-step mapping of which Cerberus agent or human reviewer discovered each Ledger-internal flaw.

Cite this record

DiggingBeagle. “Ledger fixed Ethereum signing-flow flaws found during internal automated/AI-assisted review.” First seen Aug 22, 2026. https://diggingbeagle.com/cases/ledger-fixed-ethereum-signing-flow-flaws-found-during-internal-automated-ai-assi/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.