Ledger CTO urges AI bug hunter responsibility, warns against ‘attention farming’

Summary

Ledger and Trezor are urging more responsible disclosure of security bugs in hardware wallets. Ledger CTO Charles Guillemet said AI is making vulnerabilities easier to find and exploit, but some researchers publish flaws before fixes are ready, increasing user risk. He recommended private reporting first, then agreeing on a disclosure timeline, often around 90 days, with flexibility based on severity and fix complexity. Trezor security head Jan Komárek agreed, saying the timeline is a commitment for vendors too: researchers should coordinate disclosure, publish only after the window, and go public if a fix is not delivered in time. The call comes amid heightened concern over hardware wallet security following major thefts and a Trezor-related data breach.