Ledger and Trezor call for responsible AI bug disclosure after Coldcard thefts breach $100 million
Hardware wallet makers urge AI researchers to report vulnerabilities privately first before publishing findings.
Ledger Chief Technology Officer Charles Guillemet announced that artificial intelligence has made security vulnerabilities easier to find and exploit. He stated that some researchers are publishing these findings before fixes are available, a practice he labeled attention farming. Guillemet recommended reporting bugs privately and agreeing on a timeline for patches before releasing details. Jan Komárek, Trezor's head of security, supported this approach. He noted that ninety days is a standard default window, with flexibility based on flaw severity and repair requirements. Komárek suggested researchers should contact the vendor first to agree on a schedule. If the vendor fails to ship a fix within that period, researchers may then publish. Hardware wallet security has attracted scrutiny following Coldcard thefts exceeding $100 million and a breach at Trezor's shipping provider that exposed tens of thousands of customers' personal data.