Ledger and Trezor push responsible vulnerability disclosure, warn against 'attention farming'

Editorial illustration: Two hardware wallet devices and a brass-framed hourglass sit beneath a clear glass display cover on a dark rectangular base.

In brief

  • Ledger CTO Charles Guillemet warns AI has made bugs easier to find and exploit
  • Both vendors urge private reporting with agreed timelines before public disclosure
  • Guillemet criticizes early disclosure as 'attention farming with someone else's risk'

AI and the speed of vulnerability discovery

Artificial intelligence has made bugs easier to find and exploit, according to Guillemet. The shift has intensified pressure on both researchers and vendors to act faster. Yet Guillemet characterized some researchers publishing findings before fixes are available as "attention farming with someone else's risk," underscoring a tension between transparency and responsible practice.

The CTO's critique points to a real problem: early disclosure can leave users exposed while vendors race to patch. Guillemet urged researchers to report bugs privately and agree on a timeline for fixes before publishing details. He cited 90 days as a common default disclosure timeline, with flexibility depending on flaw severity and fix complexity.

The vendor's side of the commitment

Trezor's head of security sees the 90-day window as mutual accountability. "Ninety days is a commitment on the vendor, not just on the researcher," Jan Komárek told Cointelegraph. He outlined a clear workflow: researchers come to Trezor first, agree on a timeline, then publish findings in full. If Trezor fails to ship a fix within that window, researchers should publish anyway.

This framing rejects the idea that vendors get a free pass to delay indefinitely. It's a call for transparency with guardrails, not a blank check for silence.

Why the timing matters now

Hardware wallet security has come under scrutiny after Coldcard thefts exceeded $100 million. Additionally, a data breach at Trezor's shipping provider exposed tens of thousands of customers' personal information. These incidents have made the industry's vulnerability response posture a matter of real user safety. The call for responsible disclosure isn't abstract; it's a response to concrete threats.