Ledger chief technology officer Charles Guillemet has publicly called out a growing practice among AI-assisted security researchers: publishing hardware wallet vulnerabilities before fixes are ready. He labelled the behaviour ‘attention farming with someone else’s risk.’
The core demand: private disclosure first
In a post on X, Guillemet said artificial intelligence has made software bugs significantly easier to discover and exploit, raising the stakes for how researchers handle what they find. His prescription is straightforward: report flaws privately, agree on a remediation timeline with the vendor, and only go public once a patch is shipped or the window expires.
Guillemet cited 90 days as the widely accepted default period, while acknowledging that timeline should flex depending on how severe the vulnerability is and how complex the fix turns out to be.
Trezor aligns on the 90-day standard
Jan Komárek, head of security at Trezor, reinforced that position, framing the 90-day window as an obligation that cuts both ways.
‘Ninety days is a commitment on the vendor, not just on the researcher,’ Komárek said.
He set out a clear sequence for researchers to follow: approach the vendor first, lock in a timeline together, publish the full findings once the window closes, and if the vendor fails to ship a fix within the agreed period, publish regardless.
‘Researchers: come to us first, agree a timeline, then publish in full, and if we fail to ship a fix in that window, publish anyway,’ Komárek said.
Why the issue matters now
Hardware wallet security has come under heightened scrutiny recently. Coldcard-related thefts have surpassed $100 million, and a data breach at Trezor’s shipping provider exposed the personal information of tens of thousands of customers.
The AI factor
Guillemet’s stated reason is that AI has made bugs easier both to find and to exploit, which shortens the gap between a flaw becoming known and being used against someone.
The argument has a second side that neither company addresses. Coordinated disclosure asks a researcher to sit on a finding while the people using the affected device remain unaware it exists, and researchers have historically gone public early when they judged a vendor to be moving too slowly. Komárek’s own formulation concedes the point, since it explicitly permits publication once a vendor misses the window. Neither company offered a figure for how quickly it has shipped fixes in practice.
For anyone holding a hardware wallet, that is the trade. A patch arrives before the exploit becomes public, which is worth having. The cost is that a flaw can sit in a device you already own for up to three months without you being told.


