No Ledger user was hacked.
What's described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app.
The issue was already identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post. The security bulletin has been public since then:
donjon.ledger.com/lsb/.
There is no evidence of exploitation in the wild.
A word on how this works, because it matters:
All software has bugs. Hardware wallets are no exception. That's why updateability is a core part of Ledger's security architecture: when a vulnerability is found, whether by our own Donjon team or by external researchers, we can patch every device in the field. A wallet that can't be updated can't be fixed.
This is a process we run continuously, not a one-off. We ship regular security updates, publish a security bulletin on the Ledger Donjon site
donjon.ledger.com, and work with external researchers through our bug bounty program. That track record, finding, fixing, and disclosing, is what security maturity looks like. The alternative isn't wallets without bugs; it's wallets where you never hear about them.
What to do: update your firmware applications to the latest available and Ethereum app to 1.22.3+ via Ledger Wallet, and verify the app version on your device, not just the firmware. Apps and firmware update separately.