Crypto

Ledger and Trezor Ask Bug Hunters for 90 Days Before Going Public

Both companies want vulnerabilities reported privately with a 90-day window before publication. Trezor's security head says the clock binds the vendor too, and researchers should publish anyway if no fix arrives.

⏱ 3 min read Crypto
Quick Summary
  • Ledger CTO Charles Guillemet branded premature vulnerability disclosure 'attention farming with someone else's risk,' citing AI as the accelerant behind faster bug discovery.
  • Trezor security head Jan Komu00e1rek said the 90-day remediation window is a binding commitment on vendors as much as researchers, and urged full publication if vendors miss the deadline.
  • The warnings arrive against a backdrop of Coldcard thefts exceeding 100 million dollars and a Trezor shipping-provider breach exposing tens of thousands of customers' personal data.

Ledger chief technology officer Charles Guillemet has publicly called out a growing practice among AI-assisted security researchers: publishing hardware wallet vulnerabilities before fixes are ready. He labelled the behaviour ‘attention farming with someone else’s risk.’

The core demand: private disclosure first

In a post on X, Guillemet said artificial intelligence has made software bugs significantly easier to discover and exploit, raising the stakes for how researchers handle what they find. His prescription is straightforward: report flaws privately, agree on a remediation timeline with the vendor, and only go public once a patch is shipped or the window expires.

Guillemet cited 90 days as the widely accepted default period, while acknowledging that timeline should flex depending on how severe the vulnerability is and how complex the fix turns out to be.

Trezor aligns on the 90-day standard

Jan Komárek, head of security at Trezor, reinforced that position, framing the 90-day window as an obligation that cuts both ways.

‘Ninety days is a commitment on the vendor, not just on the researcher,’ Komárek said.

He set out a clear sequence for researchers to follow: approach the vendor first, lock in a timeline together, publish the full findings once the window closes, and if the vendor fails to ship a fix within the agreed period, publish regardless.

‘Researchers: come to us first, agree a timeline, then publish in full, and if we fail to ship a fix in that window, publish anyway,’ Komárek said.

Why the issue matters now

Hardware wallet security has come under heightened scrutiny recently. Coldcard-related thefts have surpassed $100 million, and a data breach at Trezor’s shipping provider exposed the personal information of tens of thousands of customers.

The AI factor

Guillemet’s stated reason is that AI has made bugs easier both to find and to exploit, which shortens the gap between a flaw becoming known and being used against someone.

The argument has a second side that neither company addresses. Coordinated disclosure asks a researcher to sit on a finding while the people using the affected device remain unaware it exists, and researchers have historically gone public early when they judged a vendor to be moving too slowly. Komárek’s own formulation concedes the point, since it explicitly permits publication once a vendor misses the window. Neither company offered a figure for how quickly it has shipped fixes in practice.

For anyone holding a hardware wallet, that is the trade. A patch arrives before the exploit becomes public, which is worth having. The cost is that a flaw can sit in a device you already own for up to three months without you being told.

⚖️ Our Verdict ⚖️ Watch and Wait

Coordinated disclosure is the sensible default, and Komárek's point that the 90-day clock binds the vendor as much as the researcher is the fairest thing said here. But this is the vendors' side of a contested argument, made by the vendors, with no researcher quoted in reply and no figure from either company on how quickly it actually ships fixes. For anyone holding one of these devices the trade is worth understanding: a patch before the exploit is real protection, and the price of it is that a flaw can exist in your wallet for three months without you knowing.