Prominent hardware wallet manufacturers Ledger and Trezor have advocated for greater accountability in the disclosure of security flaws.
Through a Monday statement on X, Ledger chief technology officer Charles Guillemet noted that artificial intelligence has simplified the process of discovering and exploiting software weaknesses. Nevertheless, certain investigators are releasing their discoveries publicly prior to patch availability, a trend he labeled as “attention farming with someone else’s risk.”
Guillemet pressed security analysts to submit bug reports confidentially and coordinate a schedule for patches prior to disclosing information. He pointed out that 90 days serves as a standard baseline, subject to adjustment determined by the critical nature of the vulnerability and the effort required to resolve it.
“Ninety days is a commitment on the vendor, not just on the researcher,” Jan Komárek, Trezor’s head of security, told Cointelegraph.
“Researchers: come to us first, agree a timeline, then publish in full, and if we fail to ship a fix in that window, publish anyway,” he said.
Security surrounding hardware wallets has faced increased examination following Coldcard thefts surpassing $100 million alongside a security incident at Trezor’s logistics vendor that leaked the personal data of tens of thousands of users.
Related: Trezor says data breach affects another 67K US customers
Originally published at https://cointelegraph.com/news/ledger-trezor-warn-ai-bug-hunters-attention-farming?utm_source=rss_feed&utm_medium=rss&utm_campaign=rss_partner_inbound.