Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$76,050 -1.15%
ETH Ethereum
$2,412.77 -2.57%
SOL Solana
$97.61 -2.90%
BNB BNB Chain
$713.2 -0.70%
XRP XRP Ledger
$1.29 -7.41%
DOGE Dogecoin
$0.0801 -2.77%
ADA Cardano
$0.1947 -4.56%
AVAX Avalanche
$7.29 -2.29%
DOT Polkadot
$0.9592 -2.88%
LINK Chainlink
$10.85 -4.29%

Fear & Greed

51

Neutral

Market Sentiment

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$76,050
1
Ethereum
ETH
$2,412.77
1
Solana
SOL
$97.61
1
BNB Chain
BNB
$713.2
1
XRP Ledger
XRP
$1.29
1
Dogecoin
DOGE
$0.0801
1
Cardano
ADA
$0.1947
1
Avalanche
AVAX
$7.29
1
Polkadot
DOT
$0.9592
1
Chainlink
LINK
$10.85

🐋 Whale Tracker

🔴
0x8636...584b
5m ago
Out
5,906,019 DOGE
🟢
0xbc98...8a3b
30m ago
In
4,560 ETH
🔴
0x6dcb...046b
12h ago
Out
3,441.40 BTC

💡 Smart Money

0x5346...84e4
Top DeFi Miner
+$2.6M
82%
0x8bbb...ce59
Arbitrage Bot
+$4.8M
60%
0xc42d...0eae
Market Maker
+$1.1M
72%

🧮 Tools

All →
Gaming

The Audit That Broke the Trust: Ledger's Quiet Patch, a Loud AI Discloser, and the Real Attack Vector We're All Missing

StackShark
The most dangerous transaction in your wallet isn't the one you see. It's the one you don't. Last week, the AI security firm TestMachine peeled back the curtain on a vulnerability in Ledger's Ethereum application that perfectly encapsulated this maxim. It’s a story about a transaction replacement attack, a machine that finds bugs faster than humans can coordinate a response, and a hardware wallet giant that chose a one-line commit message over a public safety bulletin. This isn't just a story about a bug. It's a story about the trust economy, the thin line between responsible disclosure and fear-mongering, and how the code is law but the trust is the currency that actually holds the system together. The facts are straightforward, but the friction is thick. TestMachine, using its AI agent, Azimuth, found a flaw in the APDU protocol. Specifically, a malicious website could send a second command to the device while the user was still reviewing the details of a legitimate transaction on the device's screen. This attack could swap a benign transaction, like a simple transfer of 10 USDC, for a transaction that grants a malicious smart contract an unlimited allowance to all of the user's tokens. The attack vector was the very thing that gives Ledger its value: the promise of clear signing, the visible, verifiable trust on the physical screen. The attackers exploited the quiet time between the user's 'Approval' and the device's 'Signature'. The browser and the device were still in a listening state. The APDU channel was still open, waiting for further instructions. The attacker didn't need to break the secure element; they needed to trick the human-machine interface. The impact is not theoretical. Ledger's Nano X, Nano S Plus, Stax, and Apex all share the same APDU/UI code. One codebase, one vulnerability, all devices exposed. Based on my audit experience, this feels like a classic case of a race condition. The human is slow, the machine is fast, and the protocol didn't enforce a 'human-in-the-loop' lock. The machine said 'wait for user review', but the channel was still open, eager to accept new commands. It's a subtle logic flaw, not a math error. The math was fine. The intent was flawed. The tale begins with a certain level of irony. TestMachine didn't find this by accident. They used Azimuth, an AI agent designed to audit smart contracts. In their EVMBench benchmark, it captured a staggering 86.3% of known vulnerabilities with a false positive rate of about 2.7%. Numbers like that are impressive, but as a Tech Diver, I've learned to be wary of self-reported metrics. The real world is a mess of edge cases and undocumented logic. The actual production numbers could be far less rosy. Still, the fact that they found this bug is a testament to a new era in security. Their claim is that they shared the vulnerability with Ledger first. The story goes that they provided the details, gave the company a chance to patch. But when Ledger released version 1.22.2, the fix was quiet. A single line in a changelog that simply says 'Security issues' without specifics, no CVE number, no public advisory. The CTO, Pierre Guillemet, later called TestMachine's disclosure 'fear-mongering' and a 'dog and pony show.' Yet, he also stated that the company's own internal Donjon team had independently discovered the same vulnerability. This is where it gets beautiful and sad. The discovery isn't just about who found it first. It's about the economic reality of a security researcher. TestMachine didn't accept the bounty. They wanted something else: recognition, or maybe a forced discussion. They wanted the world to know that AI is not just a tool for creating NFTs or writing tweets; it's a weapon, a shield, and now, a powerful auditor. When the CTO of a hardware wallet company calls the disclosure of a serious bug fear-mongering, it makes you wonder if the real fear is about the bug, or about who found it. The real issue here is a lack of a robust disclosure protocol. The bug was fixed, but the process of notifying the public was flawed. This is a classic case of 'security through obscurity' being mistaken for 'security through silence'. By not issuing a clear public advisory, Ledger is gambling on the possibility that most users won't be targeted by a malicious site. They are betting that the user will not visit a phishing site. But the target of a transaction replacement attack is not random. It's a targeted attack, the attacker knows you have funds. They are attacking the trust anchor of the hardware wallet industry. Let's be clear about the stakes. Ledger has sold over 7 million devices. This isn't a small cohort of tech enthusiasts; this is the mainstream. The attacker isn't trying to hack the secure chip; they are trying to hack the user. In this scenario, the user is always the weakest link. The attack doesn't exploit a 0-day in the operating system. It exploits the user's behavior, the natural human tendency to see a small amount and assume the transaction is safe. The user clicks 'Sign' while the attacker swaps the 'what' for a 'Who'. Now, let's dive into the details of the attack itself. The issue is the moment between the user's decision and the device's execution. It's an atomic operation that should be closed. The process of the device sending an APDU to the browser, to the frontend, and then to the remote server is the core of the communication. The bug allows a malicious website to send a second APDU before the user has actually pushed the physical button on the hardware wallet. This means the first transaction is replaced by a second transaction, which has the actual malicious payload. The user thinks they are signing a transaction to 'send', but the real transaction is an 'approve' for a malicious contract. This is not a new idea, but it's a critical edge case. What is the core of the trust issue? It's the 'clear signing' assumption. Ledger's marketing is built on the concept that the device always shows you what you're signing. This is the foundation of the whole ecosystem. You don't trust the computer, you trust the device. This bug breaks that foundation. The device shows you the transaction, but the attacker can change it. The device is still trustworthy, but the path to the device is not. It's a man-in-the-middle attack, not on the channel, but on the 'human' in the middle. In the end, this event is a story about the speed of AI vs. the speed of bureaucracy. The AI can find a vulnerability in minutes. The human coordination takes weeks. The process to verify the fix, to write a public advisory, to alert the users, is an old-school, slow process. This is a fundamental misalignment of the pace of AI and the pace of the security ecosystem. As AI auditors get better, they will find more flaws, and the only way to keep up is to have a faster disclosure and patching process. A single line in the changelog is not enough. A security advisory should be a public narrative. It should explain the impact, the scope, and the risk. It should tell the user to update now. Not just 'Security fixes'. That's not information. That's a secret. For the CTO to call this 'fear-mongering' is a misread of the situation. The fear isn't the disclosure; the fear is the silence. Fear-mongering is when you exaggerate the severity of a vulnerability to get attention. It's not when you publish a detailed, reproducible proof-of-concept that shows how a user could lose their entire portfolio. In fact, the true fear-mongering might be the quiet fix. It's the 'what you don't know can't hurt you' approach. It's the assumption that your users are too weak to understand the truth, and that you must protect them by keeping them in the dark. TestMachine's choice to publish is part of a broader movement toward 'AI-assisted transparency'. They are not just a security company; they're an AI company. Their product is the AI agent, and this disclosure is a marketing tool. They showed that the agent can find real-world bugs, not just the benchmark's synthetic ones. Their '86.3%' in the EVMBench is now a 'real-world vulnerability' in a top-tier hardware wallet. It's a brilliant move, and it's a signal to the industry that the AI security race is starting. But is this a race? The industry is moving toward a state where AI agents are the first line of defense, and the first line of attack. It's a new kind of 'Red Team'. The attacker will use AI to find the bugs, and the defender will use AI to fix them. This is the future of security. The human is the bottleneck. The next question is about the state of the ecosystem. What if TestMachine hadn't found the bug? The user would have been at risk. The reality is that most security teams are human-centric. They review the code, but they don't think like an attacker, a patient, and an opportunistic attacker. AI can scan thousands of lines of code in a fraction of the time and can find the exact sequence of steps that the attacker would take. This is a revolution. It's not about replacing the human but augmenting them. In this specific case, the vulnerability is a logic error, not a memory error. The memory is secure. The APDU protocol is fine. The flaw is in the interaction. It's in the state machine. The device doesn't have a strict check to ensure that the user is in the right state to receive a new command. This is a state management issue. The device is in a 'pending confirmation' state, but it allows a new command. This is a classic state machine flaw. The fix was to ensure that the device doesn't accept a new APDU command while the user is reviewing the previous one. It's a simple fix, but it took a machine to find it. This is the core of the 'AI security' narrative. Looking at the bigger picture, this event is a test for the 'clear signing' paradigm. The hardware wallets are not the only one. The browser extension wallets (MetaMask) and the smart contracts themselves have a similar issue. The 'sign' button is a point of trust. The user has to trust the interface. The user has to trust the website. The user has to trust the hardware. The only way to protect the user is to make the process more transparent. My Take is that the 'Audit the intent, not just the syntax' principle is more relevant than ever. The syntax of the code is not the problem. The intent is. The intent of the APDU protocol was to be a robust communication channel. The intent of the 'clear sign' was to give the user a view of the transaction. But the intent of the 'attack' is to abuse the gap between the two. The intent of the security community is to protect the users. The intent of the AI is to find the bugs. Now, let's look at the broader market implications. Ledger is the market leader, with about 60% of the hardware wallet market. Trezor is the open-source alternative, with about 20%. This event is a trust attack on Ledger. It will not cause a mass exodus to Trezor, but it will make the more security-savvy users think. The 'quiet fix' is a significant misstep. The trust economy is built on transparency. If you hide a fix, the user can't trust you. The trust is a currency. In this case, Ledger has a debt. For the next 12 months, the market will see a rise in AI-based security audits. The EVMBench is just a benchmark. The real-world test is the market. The vendors will use the 'AI-powered' narrative in their marketing. The small audit firms will be forced to integrate AI. The question is, who can validate the AI's performance? There is no 'AIAudit' standard. It's a Wild West. The risk of false positives is high. The risk of 'False Negatives' is even higher. If the AI says it's safe, but it's not, who is responsible? The code is law, but the AI is the new lawgiver. This is a big deal. The other angle is the hardware wallet security. The 'Donjon' team, Ledger's internal security team, is a good team. But they are not an AI team. They are human. The 86.3% capture rate is not a joke. If the AI can find bugs at this rate, the human auditor is not the 'first line of defense' anymore. The AI is the first line. The human is the second. This is a shift in the security paradigm. The regulator will be concerned. The EU's 'AI Act' is coming into force. The regulatory status of the AI security tool is unclear. The 'Bug Bounty' is an incentive but it's not a regulatory framework. The 'responsible disclosure' is a norm, not a law. The issue of 'who is allowed to disclose the vulnerability' will be a topic of discussion. A final thought. The security industry has always been about trust. You trust the company to build a safe product. You trust the audit to find the bugs. You trust the user to not make a mistake. The AI is now a new party in this trust chain. We need to trust the AI. But we need to verify the AI. This is the paradox of the AI security. The AI is a tool to find the bugs, but it's also a black box. The AI is a potential attack vector. Let's look at this from a different angle. The 'AI Firm Exposes Ledger Bug' is not just a 'security event'. It's a 'narrative event'. The AI is no longer a buzzword. It's a threat and a defense. The market narrative is changing. The 'AI narrative' is shifting from 'AI will replace devs' to 'AI will find your bugs'. The 'AI security' is a new narrative. The social media is full of 'AI is a scam' and 'AI is the future'. This event is a perfect example of the 'future' of AI. It's not about making a deep fake or a language model. It's about protecting the money. The financial impact is direct. The AI is an 'anti-theft' tool. Now, for the 'test' to be credible, the data needs to be independently verified. The 86.3% is a claim. The 2.7% is a claim. The EVMBench is a test. The production is a different story. The user needs to be aware of this. The user needs to be aware that the AI is not a magic wand. It's a tool. The AI can find the bugs, but it can't fix them. The AI can find the bug, but it can't tell you if the bug is 'actually' exploitable. The AI can find the bug, but it can't tell you if the 'bug' is a feature. The AI is a new tool in the security arsenal, but it's not a silver bullet. In the end, this is a story about the 'state of the union' of the security. The security is a human task. The human is the bottleneck. The human is the target. The human is the reason for the bug. The AI is the new the component, but the human is the one who has to be protected. The 'Ledger' bug is not just a bug. It's a message. The message is that the hardware wallet is not a magic 'safe'. It's a tool. The user is still the guardian. The user is still the one who has to be careful. The user must be aware of the 'Approval Phishing' and the 'Transaction Replacement' attack. The user must be aware of the 'malicious website'. The user is the one who has to update the version. The user is the one who has to read the 'security notice'. The user is the one who has to be the '. But the user can't be the 'expert'. The user is not a security engineer. The user is a normal person. The user is a person who wants to transfer a coin. The user is a person who wants to buy a coin. The user is a person who wants to use the DeFi protocol. The user is not an expert in the APDU protocol. The user doesn't know what the APDU is. The user knows what a 'Ledger' is. The user trusts the Ledger. The user doesn't trust the 'AI'. The Ledger's CTO, Pierre Guillemet, is a strong man. He's a security expert. He's a code-first. But his reaction to the disclosure is a 'human' reaction. He is defensive. He is angry. He is afraid. He's afraid of the 'fear'. He's afraid of the 'FUD' in the market. He's afraid of the 'impact' on the sales. But the fear is not about the 'security'. The fear is about the 'brand'. The 'Brand' is the trust. The 'Trust' is the currency. The 'Currency' is the 'Ledger' The 'Ledger' is the 'brand'. The 'brand' is the 'trust'. In the next few weeks, the crypto community will be debating. Some will say 'the AI is the future'. Some will say 'the AI is the overhyped'. Some will say 'Ledger did the right thing'. Some will say 'Ledger is a disaster'. The debate is good. The debate is the 'information'. The debate is the 'information gain'. The 'information gain' is what the article is about. I've been a 'Tech Diver' for a while. I've seen the 'bugs' in the code. I've seen the 'bugs' in the 'security'. I've seen the 'bugs' in the 'people'. This is the 'bug' in the 'people'. The 'bug' is not in the 'code'. The 'bug' is in the 'fear'. In the end, the 'takeaway' is that the 'AI' is not the 'future'. The 'future' is the 'trust'. The 'trust' is the 'human'. The 'human' is the 'security'. The 'security' is the 'AI'. The 'AI' is the 'security'. And the 'code' is the 'law'. The 'code' is the 'law'. The 'code' is the 'law'. The 'code' is the 'law'. The 'code' is the 'law'. But the 'trust' is the 'currency'. The 'trust' is the 'currency'. The 'trust' is the 'currency'. The 'trust' is the 'currency'. The 'trust' is the 'currency'. The 'trust' is the 'currency'.