Digital Wallet

Story: Ledger CTO Calls Out “Attention Farming” as AI Risks Exposing Wallet Vulnerabilities

By Evie Vavasseur

1 / 15

The 90-Day Window Debate. Guillemet referenced a 90-day disclosure window as a kind of industry standard — the period…

2 / 15

Real Losses, Real Breaches. Both Guillemet and Komárek are speaking against a backdrop that's pretty grim.

3 / 15

What Researchers Are Being Asked to Do. The ask from Ledger and Trezor is pretty clear. Find a bug? Don't tweet it. Don't post a writeup.

4 / 15

Charles Guillemet is fed up. Ledger's CTO went public recently with a sharp critique aimed squarely at security researchers who rush to publish vulnerability findings before…

5 / 15

The timing matters. Artificial intelligence has made it dramatically easier to spot software bugs, which means the window between discovery and potential exploitation is…

6 / 15

Guillemet referenced a 90-day disclosure window as a kind of industry standard — the period vendors should get to address a reported vulnerability before researchers go public.

7 / 15

Jan Komárek from Trezor backed him up. Komárek's take is that the 90-day period isn't just a grace period handed to vendors — it's a mutual commitment.

8 / 15

It's a reasonable framework. And it's not new — coordinated disclosure has been a standard practice in enterprise cybersecurity for years.

9 / 15

Both Guillemet and Komárek are speaking against a backdrop that's pretty grim. Coldcard wallets have seen thefts exceeding $100 million.

10 / 15

Those two incidents alone make the case for why sloppy disclosure practices are genuinely costly. It's not hypothetical. The money is gone. The data is out there.

11 / 15

Hardware wallets are supposed to be the safest way to store crypto. They sit offline, away from exchange hacks and browser exploits.

12 / 15

Read also: Harmony Proposes Shutdown and Migration to Ethereum Following 109,000-Transaction Exploit

13 / 15

What Guillemet is pushing back against is the researcher who finds something, sits on it just long enough to write a dramatic blog post, and then drops it publicly with zero…

14 / 15

The AI angle makes it more urgent. Security researchers now have tools that can scan codebases and flag potential vulnerabilities at a speed that wasn't possible a few years ago.

15 / 15

Komárek's framing is worth sitting with. He wants researchers to see the 90-day window as a partnership, not a delay tactic.

The Currency Analytics

Want the full story?