Could AI make hardware wallet vulnerabilities harder to control? The Ledger CTO is urging researchers to rethink early bug disclosures before they put users at greater risk.

The Ledger CTO has urged security researchers to think twice before publicly revealing hardware wallet vulnerabilities before companies have had time to fix them. Charles Guillemet, Ledger’s chief technology officer, said AI has made it much easier to discover and exploit software bugs, increasing the need for responsible security disclosures.

In a Monday post on X, Guillemet criticized researchers who publish details of vulnerabilities before fixes are ready. He described the practice as “attention farming with someone else’s risk,” arguing that public disclosures can create fear among users and give attackers an advantage.

Why Is Responsible Disclosure Becoming More Important?

Guillemet asked researchers to contact wallet makers privately when they discover a security flaw. He recommended agreeing on a reasonable period for fixing the issue before making the technical details public.

He pointed to 90 days as a common starting point, although the timeline could change depending on how serious the vulnerability is and how difficult it is to fix. Trezor also backed the approach. Jan Komárek, the company’s head of security, stressed that the responsibility should not fall entirely on researchers.

“Ninety days is a commitment on the vendor, not just on the researcher,” Komárek told Cointelegraph.

He added that researchers should approach vendors first, agree on a timeline and then publish the full findings. If a company fails to deliver a fix within that period, public disclosure can follow.

Could Publicity Around Bugs Put Users at Risk?

The warning comes as hardware wallet security faces increased attention. Coldcard thefts have exceeded $100 million, while a breach involving Trezor’s shipping provider exposed the personal information of tens of thousands of customers. Trezor has also said another 67,000 customers in the US were affected.

Guillemet argued that some disclosures go beyond legitimate security research. He pointed to cases where already-fixed vulnerabilities are presented as ongoing threats, unpatched flaws are revealed too early, or teaser-style leaks are used to attract attention. According to Guillemet, such actions can create unnecessary panic. Even when users do not suffer direct financial losses, fear could lead some people to abandon self-custody.

Ledger, Trezor, Foundation Devices, AnchorWatch and SEAL have expressed support for coordinated disclosure as an industry standard. Guillemet also reminded users to keep their software updated and follow basic security practices.

As Business Fortune observes, AI continues to accelerate vulnerability research and hardware wallet companies are likely to place greater emphasis on coordinated disclosure. The industry’s future may depend not only on finding security flaws faster, but also on giving vendors enough time to fix them before those flaws become a wider threat.

FAQs

What did the Ledger CTO warn about?

Charles Guillemet warned that publicly revealing vulnerabilities before fixes are available can increase risks for users.

Why is AI important to the discussion?

AI has lowered the barrier to discovering vulnerabilities, making security flaws easier to identify and potentially exploit.

What is the suggested 90-day timeline?

It is a common period suggested for vendors to address a reported vulnerability before researchers publicly disclose the details.

What did Trezor say about responsible disclosure?

Trezor’s head of security said vendors should also take responsibility by working toward a fix within the agreed timeline.

Why is hardware wallet security under scrutiny?

Recent incidents, including major Coldcard thefts and a Trezor-related shipping provider data breach, have increased attention on security across the hardware wallet industry.