Ledger CTO urges AI bug hunter responsibility, warns against ‘attention farming’
Hardware wallet makers Ledger and Trezor called for more responsible disclosure of security vulnerabilities.
Guillemet urged researchers to report bugs privately and agree on a timeline for fixes before publishing details. He cited 90 days as a common default, with flexibility depending on the severity of the flaw and the work needed to fix it.
“Ninety days is a commitment on the vendor, not just on the researcher,” Jan Komárek, Trezor’s head of security, told Cointelegraph.
“Researchers: come to us first, agree a timeline, then publish in full, and if we fail to ship a fix in that window, publish anyway,” he said.
Hardware wallet security has come under scrutiny after Coldcard thefts exceeded $100 million and a data breach at Trezor’s shipping provider exposed tens of thousands of customers’ personal information.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
'The chain is now earnings': Bernstein sees 31% upside for Robinhood as fees top Solana, BNB Chain
Zcash jumps 2,496%, sector market cap climbs to $33.6 billion
Lightbridge targets mid-2030s lead test assemblies via DOE-backed SHED pilot plant at INL
Gold X2 Mining hits 40.4 m at 2.05 g/t gold at Span prospect near Moss deposit in Ontario
