Ledger's Chief Technology Officer Calls for Ethical Conduct from AI-Powered Bug Hunters

Ledger's Chief Technology Officer Calls for Ethical Conduct from AI-Powered Bug Hunters

Hardware wallet manufacturers Ledger and Trezor are calling on security researchers to follow responsible disclosure practices and allow adequate time for vulnerability patches as artificial intelligence accelerates bug discovery.

Leading hardware wallet manufacturers Ledger and Trezor have issued appeals for greater accountability in the disclosure of security flaws and vulnerabilities.

Through a Monday statement shared on X, Charles Guillemet, who serves as Ledger's chief technology officer, explained that the rise of artificial intelligence has simplified the process of discovering and leveraging security vulnerabilities. Despite this technological advancement, certain security researchers are making their discoveries public prior to the availability of patches, behavior he characterized as "attention farming with someone else's risk."

Guillemet made a strong appeal to security researchers to submit bug reports through private channels and negotiate mutually acceptable timeframes for implementing fixes prior to making details publicly available. He referenced 90 days as a widely accepted standard timeframe, while noting that adjustments may be necessary based on how critical the vulnerability is and the complexity of developing a proper solution.

"Ninety days is a commitment on the vendor, not just on the researcher,"

Jan Komárek, Trezor's head of security, told Cointelegraph

"Researchers: come to us first, agree a timeline, then publish in full, and if we fail to ship a fix in that window, publish anyway,"

he said

The security posture of hardware wallets has faced increased examination following incidents where Coldcard thefts surpassed $100 million and a security compromise at Trezor's logistics partner resulted in the exposure of personal details belonging to tens of thousands of customers.

← Torna al blog