Hardware wallet makers Ledger and Trezor are urging researchers to handle security vulnerability disclosures more responsibly as concerns grow over premature publication of bug findings. In a Monday post on X, Ledger chief technology officer Charles Guillemet said artificial intelligence has made bugs easier to find and exploit, but some researchers are sharing their findings before fixes are available. He described that approach as “attention farming with someone else’s risk” and said researchers should report bugs privately and agree on a timeline for fixes before publishing details. According to Cointelegraph, Guillemet said 90 days is a common default for disclosure, though the timeline should remain flexible depending on the severity of the flaw and the work required to fix it.
Jan Komárek, Trezor’s head of security, said the 90-day period is also a commitment for the vendor, not only for the researcher. He said researchers should contact the company first, agree on a timeline, and then publish the findings in full. Komárek added that if the company fails to ship a fix within that window, the researcher should publish anyway. The comments come as hardware wallet security faces increased scrutiny following Coldcard thefts that exceeded $100 million and a data breach at Trezor’s shipping provider that exposed tens of thousands of customers’ personal information.