News
Exchange News 26.08.2026: Ledger ETH Vulnerability
Daily Brief for the Baltic and Nordic segment: Ledger Ethereum app clear-signing vulnerability (fixed in 1.22.2) and its disclosure dispute, plus Nordic broker K33's call option deal for up to 200 BTC.
Over the past 24-48 hours, two clearly dated events in our segment: the public disclosure of a Ledger Ethereum app clear-signing vulnerability (fixed in version 1.22.2 on August 12th) alongside a dispute with the manufacturer over the disclosure, and Nordic broker K33's call option deal for up to 200 BTC on August 24th. With context on the MiCA register and watchlist.
Wednesday, 26th August 2026. This is a Day Brief format publication. Over the past 24-48 hours, our segment - crypto exchanges and CASPs, hardware wallets, crypto cards, and tax tools serving the Baltics (LV, LT, EE) and Northern Europe (FI, SE, NO, DK) - has seen two clearly dated key events: the public disclosure of a security vulnerability in the Ledger Ethereum app and the subsequent dispute with the manufacturer, as well as Nordic broker K33's deal involving a Bitcoin call option contract. Other ongoing regional developments are covered as context and a watchlist, rather than being repeated as fresh news.
Ledger Ethereum App "Clear Signing" Vulnerability Fixed
Between August 22nd-23rd, a vulnerability in the Ledger hardware wallet's Ethereum app, specifically its "clear signing" flow, was publicly disclosed. Technically, this involved a race condition in APDU command processing: a malicious desktop or browser application could theoretically send a competing command while the user was still reviewing the original transaction, replacing the transaction displayed on screen with a different one before signature confirmation. The practical risk: a user might believe they are confirming a small token transfer, but in fact authorise an unlimited token approval to an attacker's address.
Ledger states that the vulnerability was discovered by its internal security team, Donjon, using AI-assisted tools, and a fix was released in Ethereum app version 1.22.2 as early as August 12th - approximately before the public disclosure. The public warning was circulated between August 21st-23rd by a researcher using the pseudonym "TestMachine", who, according to Ledger, declined the company's bug bounty offer. Ledger's CTO, Charles Guillemet, called the public disclosure fear-mongering, emphasising that users running the latest app version are already protected.
For Baltic and Nordic users, the segment's conclusion is practical and moderate. Firstly, there have been no confirmed fund thefts in this case - unlike the Coldcard incident in early August, where funds were actually drained. Secondly, protection is simple: update the Ledger device firmware and Ethereum app to the latest version via Ledger Live. Thirdly, the incident reaffirms that clear signing and on-screen information are at the core of hardware wallet security - and that visual verification of transaction details on the device's screen itself, not just on the computer side, remains crucial. The ethical dispute over public disclosure (whether the researcher should have waited for coordinated disclosure) is an internal industry discussion; for the user, the most important fact is that a fix is available and should be installed.
K33 Deepens Bitcoin Exposure with Call Option Contract
On August 24th, Nordic crypto broker and exchange K33 (listed in Sweden and Norway) announced a structured transaction that deepens its Bitcoin exposure through its Canadian associate, Sixty Six Capital. K33 Holding AS owns approximately 46% of Sixty Six Capital. Under the deal, Sixty Six Capital entered into a 12-month call option agreement with K33 Holding AS for up to 200 BTC with a strike price of 100,000 US dollars per Bitcoin; the option can be exercised once for an amount between 100 and 200 BTC, with physical on-chain settlement by August 21st, 2027. K33 Holding, as the contract writer, received a non-refundable premium of 1,932,000 US dollars, and through its 46% stake, gains an approximate 92 BTC "look-through" effective exposure.
In context, this fits into a broader trend among Nordic exchanges, where several regional players - K33 with its Bitcoin reserve strategy, as well as previously covered Safello and Firi - combine retail exchange operations with treasury and institutional products. The assessment should be taken with caution: this is a treasury and structured product transaction, not a change in K33's exchange services for retail clients in the region. For Baltic users, the direct impact is indirect. However, the signal is consistent with what we have observed: Nordic-listed crypto companies are increasingly using balance sheets and derivatives to gain Bitcoin exposure, which in turn increases the sensitivity of their results to the price of Bitcoin.
Context: MiCA CASP Register Continues to Grow, No New Firms in the Region
As of August 25th, the MiCA CASP register maintained by ESMA reached approximately 331 licensed crypto-asset service providers. This continues a gradual increase from the end of July (321 firms on July 31st), but - consistent with our August 22nd brief's conclusion about the halt in regional growth - the latest additions are primarily from Southern Europe (e.g., Spain), and this new batch includes no new Baltic or Nordic players. The region's existing licensed CASPs (including Latvia's AlphaRoute, Bleap, and Altcoins, Finland's Coinmotion, Estonia's LHV Pank, Norway's Bare Bitcoin) remain unchanged. We continue to monitor for the next update regarding regional firms - CASP authorisation movement is the most important structural indicator for our segment.
Watchlist (Ongoing Stories, Not Fresh News)
These points are not news from the last 24 hours; we keep them on our watchlist with precise previous dates.
Coldcard (Coinkite) incident: The draining of funds caused by hardware wallet seed entropy errors was followed in our daily briefs on August 2nd-4th and weekly briefs. The total drained amount, according to industry estimates, exceeded 2,000 BTC; the figure is still an estimate. The regional conclusion remains unchanged: the risk is tied to specific Coldcard models and firmware versions, not to any Baltic or Nordic platform; affected seeds require migration to a new key.
Tangem laser attack: The laser attack discovered in July, which resets Tangem card passwords on un-updatable chips, remains in context. The manufacturer maintains that the risk to everyday users is minimal, as the attack requires physical device access and specialised equipment. No new information this week.
Goobit / BTCX management change: On August 14th, it was reported that former Bybit Nordic head Gustav Buder would become CEO of Goobit; Goobit operates Sweden's first Bitcoin exchange, BTCX, which was denied a MiCA licence. We are monitoring how this will affect BTCX's regulatory path.
Crypto card segment: Kraken launched a Mastercard network debit card in the EEA and UK in July with up to 2% cashback in Bitcoin; the product is formally available to Baltic and Nordic EEA users as well, but a separate regional rollout has not yet been announced. No new announcements this week.
Summary for Market Participants
For hardware wallet users in the Baltics and Nordics, the practical task is clear: update your Ledger device firmware and Ethereum app (version 1.22.2 or newer), check if you were affected by the Coldcard incident, and always confirm transaction details on the device's screen itself.
Nordic-listed crypto companies are increasingly gaining Bitcoin exposure through their balance sheets and derivatives. The K33 deal increases the company's results' sensitivity to the price of Bitcoin; investors should distinguish between core exchange operations and treasury positions.
The regulatory structure in the region remains stable but static: the MiCA register is growing, but the flow of new Baltic and Nordic licences has stalled in recent weeks. The next ESMA update with regional firms will be the most important signal.
Clear signing is at the core of wallet security. The Ledger case shows that even in well-protected devices, software layer errors can occur; protection relies on timely updates and visual verification of transactions.
Sources
- ESMA - Markets in Crypto-Assets Regulation (MiCA)
- crypto.news - Ledger says Ethereum signing flaw was already fixed (24.08.2026)
- CryptoBriefing - Ledger fixes vulnerability in Ethereum app's signing flows (Ethereum app 1.22.2, 12.08.2026)
- The Cyber Express - Ledger Ethereum App Clear-Signing Flaw: TestMachine Disclosure Dispute (23.08.2026)
- TradingView / Modular Finance - K33 Expands Effective Bitcoin Exposure Through Sixty Six Capital's Option for up to 200 BTC (24.08.2026)
- Kaupr - Option gives K33 added bitcoin exposure in Canada (24.08.2026)