Coinfomania says Ledger's own Donjon team disclosed the Ethereum app vulnerability, while CryptoBriefing and The Cryptonomist EN say the public disclosure came from an external security researcher/firm, TestMachine.
Coinfomania says Ledger's own Donjon team disclosed the Ethereum app vulnerability, while CryptoBriefing and The Cryptonomist EN say the public disclosure came from an external security researcher/firm, TestMachine.
The issue was disclosed by Ledger Donjon, emphasizing proactive security measures.
That changed between August 21 and 23, when a security researcher operating under the name TestMachine publicly disclosed the bug.
Security firm TestMachine disclosed the bug publicly between August 21 and 23, 2026, using an AI agent called Azimuth.
What would settle it: Ledger's own security advisory or TestMachine's original disclosure post identifying who published the finding and when.
Treat the underlying technical facts—the race condition bug, the August 12 patch in v1.22.2, and Donjon's internal discovery—as settled across all reports. The identity of who made the vulnerability public is contested and should not be repeated as fact until Ledger or TestMachine's own disclosure record is checked.
Treat the underlying technical facts—the race condition bug, the August 12 patch in v1.22.2, and Donjon's internal discovery—as settled across all reports. The identity of who made the vulnerability public is contested and should not be repeated as fact until Ledger or TestMachine's own disclosure record is checked.
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect