Ledger and Trezor, two leading hardware‑wallet manufacturers, have asked security researchers to adopt more responsible disclosure practices following the rise of artificial‑intelligence tools that accelerate bug discovery.
In a post on X, Ledger chief technology officer Charles Guillemet warned that AI has lowered the barrier to finding and exploiting vulnerabilities. He said some researchers publish findings before a fix is available, a practice he described as “attention farming with someone else’s risk.” Guillemet recommended that researchers report flaws privately and agree on a remediation timeline, citing a 90‑day period as a common default that can be adjusted for severity and the effort required to develop a patch.
Jan Komárek, Trezor’s head of security, echoed the call, stating that researchers should approach the vendor first, set a timeline, and publish the full details only if the vendor fails to deliver a fix within that window.
The appeal comes amid heightened scrutiny of hardware‑wallet security. Recent incidents include Coldcard thefts that exceeded $100 million and a data breach at Trezor’s shipping provider that exposed personal information of tens of thousands of customers, with a separate breach affecting about 67,000 U.S. users.
Both companies emphasized that a coordinated approach balances the need for transparency with the protection of users’ assets.












