Ledger and Trezor Call for Responsible Security Vulnerability Disclosure
- Ledger’s CTO, Charles Guillemet, highlighted that AI has made it easier to find and exploit bugs.
- He criticized researchers for publishing vulnerabilities before fixes are available, labeling it “attention farming with someone else’s risk.”
- Guillemet suggested a standard reporting timeline of 90 days for fixing vulnerabilities before public disclosure.
- Trezor’s head of security, Jan Komárek, echoed this sentiment, urging researchers to collaborate on timelines for disclosures.
- Recent scrutiny on hardware wallet security arose after over $100 million in Coldcard thefts and a data breach affecting tens of thousands of Trezor customers.
The call for responsible disclosure comes amid rising concerns regarding hardware wallet security, particularly following significant thefts and data breaches. Both companies stress the importance of private reporting to mitigate risks associated with premature disclosures.
With over $100 million lost in Coldcard thefts, the need for a structured approach to vulnerability reporting is crucial for protecting users’ assets and information.(Source)