Ledger, Trezor Urge Responsible Disclosure by AI Bug Hunters
Hardware wallets safeguard the private keys used to control cryptocurrency, making product vulnerabilities a potential threat to customer funds. Ledger and Trezor say security researchers using artificial intelligence to find flaws more quickly must still follow coordinated disclosure practices, notifying vendors before publishing technical details that could help attackers exploit users who have yet to receive a fix.
Ledger’s chief technology officer recently urged AI-assisted bug hunters not to disclose unpatched weaknesses to attract attention. Researchers should allow vendors a remediation window of as long as 90 days to investigate reports, develop patches and alert customers, the executive said. Ledger and Trezor warned that premature publication can turn users’ exposure to theft or compromise into a tool for researchers seeking traffic and recognition.
All Coverage
2 original reportsThe Backstory
The history behind this eventThis is the first time the radar has seen this story
See the “Cryptocurrency Security” timeline →Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →