BNB $752.01 +1.30%
XRP $1.41 +0.78%
ETH $2,493.36 -0.20%
BTC $78,694.63 -0.80%
BNB $752.01 +1.30%
XRP $1.41 +0.78%
ETH $2,493.36 -0.20%
BTC $78,694.63 -0.80%
BREAKING
Digital Wallet

Ledger CTO Calls Out “Attention Farming” as AI Risks Exposing Wallet Vulnerabilities

Ledger CTO Slams "Attention Farming" as AI Makes Hardware Wallet Bugs Easier to Find
Ledger CTO Slams "Attention Farming" as AI Makes Hardware Wallet Bugs Easier to Find

Community Trust ScoreVerified

89%
Real
Verified46 votes
Updated 2 hours ago

Charles Guillemet is fed up. Ledger’s CTO went public recently with a sharp critique aimed squarely at security researchers who rush to publish vulnerability findings before vendors get a real shot at fixing them. He called it “attention farming with someone else’s risk” — and he’s not wrong to be annoyed.

The timing matters. Artificial intelligence has made it dramatically easier to spot software bugs, which means the window between discovery and potential exploitation is shrinking fast. Guillemet’s point is pretty straightforward: if a researcher can find a flaw in hours using AI tools, a bad actor probably can too. Publishing before a patch exists doesn’t just embarrass the vendor — it hands criminals a roadmap.

The 90-Day Window Debate

Guillemet referenced a 90-day disclosure window as a kind of industry standard — the period vendors should get to address a reported vulnerability before researchers go public. But he was careful not to treat that number as sacred. Severity matters. Complexity matters. A critical flaw in firmware that requires a full product update can’t realistically be patched in the same timeframe as a minor software bug, and Guillemet basically said so.

Advertisement

Jan Komárek from Trezor backed him up. Komárek’s take is that the 90-day period isn’t just a grace period handed to vendors — it’s a mutual commitment. Researchers agree to stay quiet. Vendors agree to move fast. If the fix doesn’t arrive within the agreed window, the researcher is free to publish. That’s the deal. Komárek urged researchers to approach companies first, set a timeline together, and only go public if the vendor fails to deliver.

It’s a reasonable framework. And it’s not new — coordinated disclosure has been a standard practice in enterprise cybersecurity for years. But the crypto hardware wallet space is still kind of catching up, and the stakes are high enough that the lag is starting to show.

Real Losses, Real Breaches

Both Guillemet and Komárek are speaking against a backdrop that’s pretty grim. Coldcard wallets have seen thefts exceeding $100 million. That’s not a rounding error — that’s a nine-figure loss tied to hardware wallet security failures. And Trezor itself took a hit when a data breach at its shipping provider exposed the personal information of tens of thousands of customers. Not wallet funds, but names, addresses, contact details — the kind of data that makes phishing attacks a lot more targeted and dangerous.

Those two incidents alone make the case for why sloppy disclosure practices are genuinely costly. It’s not hypothetical. The money is gone. The data is out there.

Hardware wallets are supposed to be the safest way to store crypto. They sit offline, away from exchange hacks and browser exploits. But they’re not immune to software vulnerabilities, supply chain breaches, or the kind of social engineering that gets a lot easier when an attacker already knows your name and shipping address. The Trezor breach is a good example of how security can fail at a layer that has nothing to do with cryptography.

What Researchers Are Being Asked to Do

The ask from Ledger and Trezor is pretty clear. Find a bug? Don’t tweet it. Don’t post a writeup. Contact the vendor privately, agree on a timeline, and give them a real chance to fix it. If they stall or go dark, then publish. That’s fair.

What Guillemet is pushing back against is the researcher who finds something, sits on it just long enough to write a dramatic blog post, and then drops it publicly with zero coordination. That approach gets attention. It probably gets job offers. But it also leaves users exposed during the gap between disclosure and patch deployment — and that gap can be weeks or months depending on how complex the fix is.

The AI angle makes it more urgent. Security researchers now have tools that can scan codebases and flag potential vulnerabilities at a speed that wasn’t possible a few years ago. That’s genuinely useful. But it also means the volume of discovered vulnerabilities is going up, and not every researcher finding bugs with AI assistance has the same ethical training as someone who’s spent years working in enterprise security. Some of them probably don’t think much about coordinated disclosure at all.

Komárek’s framing is worth sitting with. He wants researchers to see the 90-day window as a partnership, not a delay tactic. Vendors aren’t asking for silence forever — they’re asking for enough time to actually protect their users. That’s a different thing.

The broader crypto industry has had a complicated relationship with security transparency. Full disclosure has sometimes been used to pressure companies publicly when private channels failed. That’s understandable. But Guillemet and Komárek are arguing for a default of coordination first, publicity second — and given the $100 million in Coldcard losses sitting in the background of this conversation, it’s hard to dismiss that argument.

No details were given on whether Ledger or Trezor plan to formalize their disclosure policies beyond what Guillemet and Komárek said publicly. Unclear if a joint framework is coming. For now, it’s a public call for better behavior — directed at a research community that’s moving faster than ever, thanks in part to the same AI tools that are making everyone’s job harder.

Trezor’s shipping provider breach exposed personal data for tens of thousands of customers.

Frequently Asked Questions

What did Ledger’s CTO say about AI and bug reporting?

Charles Guillemet said AI makes it easier to find and exploit software bugs, and criticized researchers who publish findings before vendors can fix them, calling it “attention farming with someone else’s risk.”

What is the 90-day disclosure window Ledger and Trezor reference?

Both Guillemet and Trezor’s Jan Komárek described a 90-day period as a mutual commitment — vendors get that window to fix reported bugs before researchers publish, with flexibility depending on severity and complexity.

What security incidents prompted this discussion?

Coldcard wallets saw thefts exceeding $100 million, and a data breach at Trezor’s shipping provider exposed the personal information of tens of thousands of customers.

Why It Matters

This critique highlights a growing tension in the crypto security landscape, where the rapid advancement of AI tools is reshaping vulnerability disclosure practices. As hardware wallets like Ledger's are central to securing digital assets, the balance between responsible reporting and the urgency for public attention becomes crucial; a misstep could expose users to significant risks. The implications of this debate extend beyond Ledger, as the broader crypto market increasingly relies on robust security measures to instill user confidence and protect against rising threats.

Community Trust IndexHigh Confidence
89%
Real
Real89%11%Fake
46 community signals

Evie Vavasseur

Evie Vavasseur is a crypto writer and digital content specialist covering the latest developments in blockchain technology, decentralized finance, and the broader digital asset ecosystem. With a keen eye for emerging trends, Evie provides accessible and insightful coverage of cryptocurrency markets, NFTs, and Web3 innovations for The Currency Analytics.

Advertisement

Related Stories