Hardware wallet manufacturers Ledger and Trezor have called for greater responsibility in the disclosure of security vulnerabilities, particularly in the context of artificial intelligence's growing role in bug discovery.
Ledger Chief Technology Officer Charles Guillemet stated on X that AI has accelerated the ease with which bugs can be found and exploited. He expressed concern over researchers publishing vulnerability details before fixes are implemented, a practice he described as "attention farming with someone else’s risk."
Guillemet urged security researchers to report bugs privately to vendors and establish an agreed-upon timeline for remediation before making the details public. He suggested that 90 days is a common default period for such disclosures, though this can be adjusted based on the severity of the flaw and the complexity of the fix.
Jan Komárek, Trezor’s head of security, echoed these sentiments, telling Cointelegraph that the 90-day period represents a commitment from the vendor. He advised researchers to approach vendors first, agree on a timeline, and then publish the full details, especially if the vendor fails to deliver a fix within the agreed window.
The call for responsible disclosure comes amid increased scrutiny of hardware wallet security. Recent incidents include Coldcard thefts exceeding $100 million and a data breach at Trezor’s shipping provider that exposed personal information of tens of thousands of customers.