News
Ledger Ethereum Patch 02.09.2026: Weekly Brief
A weekly overview for the Baltic and Nordic crypto exchange, hardware wallet, card, and tax tool segments: no new clearly datable events in the last 24 hours, so we provide a weekly review with precise dates and a watchlist.
No new clearly datable events in our segment in the last 24 hours, so we offer a weekly overview. The main datable event: in the last week of August, hardware wallet manufacturer Ledger released Ethereum app patches (1.22.2 - 13.08., 1.22.3 - 25.08.) for three vulnerabilities (LSB-023/024/025), but competitor OneKey publicly replicated the already patched bug on 27th August. No funds were stolen; users should update the app. Includes market background and watchlist.
Tuesday, 2nd September 2026. This is a 'Week Brief' format publication. In the last 24 hours, there have been no new, clearly datable significant events in our segment - crypto exchanges and CASPs, hardware wallets, crypto cards, and tax tools serving the Baltics (LV, LT, EE) and Northern Europe (FI, SE, NO, DK). Therefore, today we offer a weekly overview with precise dates. The most clearly datable segment event of the week, not yet covered in our previous issues, is a series of Ethereum app vulnerabilities and patches from hardware wallet manufacturer Ledger, which culminated in the last week of August. Older, ongoing stories are presented as context, not as fresh news.
Week's Main Event: Ledger Ethereum App Vulnerabilities and Patches
In the last week of August, a series of security vulnerabilities in Ledger's Ethereum app and their subsequent fixes garnered public attention. This event falls into the second category of our segment - hardware wallets - and is directly relevant to self-custody users in the Baltic and Nordic regions, as Ledger is one of the most widely used hardware wallets there.
The chain of events is precisely datable. On 13th August, Ledger released Ethereum app version 1.22.2, which addressed a vulnerability labelled LSB-023 - the so-called "transaction replacement" bug. According to Charles Guillemet, the company's Chief Technology Officer (CTO), this was a race condition bug in the signing logic: an attacker who already had control over communication between the device and the host (e.g., via malware or a compromised wallet app) could theoretically overwrite a pending transaction for signing while the user was still viewing a legitimate transaction - meaning one transaction was displayed on screen, but another was signed.
On 25th August, Ledger released Ethereum app version 1.22.3, which fixed two more real vulnerabilities that remained in version 1.22.2. LSB-024 was a counter overflow bug: the app used a 16-bit counter for an array of operations but stored the remaining count in an 8-bit field, causing the counter to "wrap around" to one after 257 operations, showing only the last operation even though the entire batch was authorised. LSB-025 affected the token swap flow: the app checked the token, amount, and destination but did not confirm whether the action was actually a payment, allowing a malicious swap provider to substitute a valid token approval without a device prompt.
Public discussion intensified on 27th August when Yishi Wang, founder of rival wallet manufacturer OneKey, announced that researchers had replicated the LSB-023 attack against an outdated Ethereum app version 1.22.1 in laboratory conditions. Ledger's CTO disputed this characterisation, stating that reproducing an already patched bug was not a "Ledger hack" and emphasising that the fix had been released before the public demonstration. The company also reminded users that a Software Development Kit (SDK) update 26.6.1 was released on 21st August.
Crucially: Ledger claims that no user was hacked and there is no evidence of real-world exploitation. The practical conclusion for users in the region is clear, but with an important nuance: the Ethereum app itself must be updated to version 1.22.3 or newer via Ledger Live, and the version on the device must be verified. Unlike many other cases this year, which involved device firmware, here the vulnerability is at the app level - merely updating the firmware does not resolve the issue. The broader lesson is about "blind signing" versus "clear signing": all these scenarios rely on the user not seeing or verifying the actual parameters of the transaction.
Context: 2026 - The Year of Hardware Wallet Security (as a reminder, not fresh news)
These points are not news from the last 24 hours; we include them only for background, with precise previous dates.
The Ledger Ethereum app case fits into the broader theme of hardware wallet security in 2026. Ledger itself had a separate Zilliqa app vulnerability in July (covered in our issue on 26th July), confirming that the app layer requires as regular maintenance as firmware. We followed the critical firmware patch from Swiss manufacturer BitBox, codenamed "Dixence" (version 9.26.5, published 17th August), in our weekly brief on 23rd August; there were no stolen funds, and a firmware update was sufficient. The discovery of a laser attack on Trezor Safe 7 and its TROPIC01 chip (Ledger Donjon, early June) remains in context, with the manufacturer promising improved versions by the end of the year. We followed the Coldcard (Coinkite) seed generation vulnerability and its fix (firmware 5.6.1 and 1.5.1Q, released 20th August) in a separate explanation on 24th August; this remains an ongoing story tied to specific models and firmware versions.
The common lesson for self-custody users in the region remains unchanged: hardware wallet security is not a one-off purchase but a maintenance process - both firmware and app updates must be installed only from official sources and in a timely manner, and transactions should be signed with clear signing whenever possible.
Market and Regulatory Background
On the regulatory side, no new MiCA CASP authorisations for Baltic or Nordic crypto exchanges have been registered in the last week. Publicly available CASP registry reflections as of 1st September show no new regional crypto exchanges added in the last week of August; the net increase in the ESMA registry this year is primarily driven by credit institution notifications, not regional crypto exchanges. Separately reviewed events in the region over the last week - NBX's step towards a specialised banking licence in Latvia (subsidiary registered 27th August; covered 31st August) and Norwegian crypto exchange K33's Q2 results (published 27th August) - are not retold here as fresh news but mentioned as background.
In the tax tool category (Koinly, Blockpit, Divly, and others), preparations for the EU DAC8 and CARF reporting regimes, which are gradually coming into force, continue in the background; the Finnish Tax Administration (vero.fi) is introducing a new obligation in 2026 to provide information on crypto asset services. This is not an event from the last 24 hours, but an ongoing regulatory background that will affect demand for tax tools in the region in future periods.
At a broader market level, we emphasise that price fluctuations are a macroeconomic background, not an event in our product segment; the price environment indirectly affects the volumes and revenues of regional exchanges.
Watchlist (Ongoing Stories)
Ledger Ethereum app: We are monitoring for additional technical information on LSB-023/024/025, how quickly users migrate to version 1.22.3, and whether other wallets based on similar app architectures report comparable findings.
Goobit/BTCX MiCA appeal: Following Finansinspektionen's rejection in July, the company filed both a request for reconsideration and an appeal on 23rd July; the administrative court process is ongoing, and the outcome remains open.
Coldcard incident: We continue to consider this an ongoing, not a new, event; affected seeds require migration to a new key.
Norwegian transitional regime: The MiCA transitional period ended on 30th June; we published a detailed map of local exchange (Firi, K33, NBX, Tyr Markets) CASP licences in a separate explanation on 1st September and are monitoring for further changes.
ESMA MiCA registry: We are monitoring for upcoming updates regarding Baltic and Nordic firms.
Sources
- Ledger CTO Charles Guillemet's public statements (August 2026) - https://www.ledger.com
- Decrypt, "No, Ledger Wasn't Hacked: Vulnerable Ethereum App Was Patched Before Exploit" (2026-08-27) - https://decrypt.co/376750/no-ledger-wasnt-hacked-ethereum-app-exploit
- CryptoSlate, "Ledger says the viral hack was already patched but two real bugs still needed fixing" (2026-08-28) - https://cryptoslate.com/ledger-says-the-viral-hack-was-already-patched-but-two-real-bugs-still-needed-fixing/
- crypto.news, "Ledger rejects hack claim after OneKey recreates bug" (2026-08-28) - https://crypto.news/ledger-rejects-hack-claim-after-onekey-recreates-bug/
- The Cryptonomist, "Ledger Ethereum Vulnerability Fixed Quietly in August 2026" (2026-08-24) - https://en.cryptonomist.ch/2026/08/24/ledger-ethereum-vulnerability/
- Cointelegraph, "BitBox Patches Code Execution and Bitcoin Lockup Flaws" (context) - https://cointelegraph.com/news/bitbox-patches-severe-wallet-firmware-flaws