
Ledger and Trezor said researchers have a responsibility to publish their findings if vendors fail to fix bugs within an agreed disclosure window.
Hardware wallet makers Ledger and Trezor called for more responsible disclosure of security vulnerabilities.
In a Monday post on X, Ledger chief technology officer Charles Guillemet said artificial intelligence has made bugs easier to find and exploit. However, some researchers are publishing their findings before fixes are available, a practice he called “attention farming with someone else’s risk.”
Guillemet urged researchers to report bugs privately and agree on a timeline for fixes before publishing details. He cited 90 days as a common default, with flexibility depending on the severity of the flaw and the work needed to fix it.
Read more
cointelegraph.com
