Digital Wallet
By Evie Vavasseur
1 / 15
The 90-Day Window Debate. Guillemet referenced a 90-day disclosure window as a kind of industry standard — the period…
2 / 15
Real Losses, Real Breaches. Both Guillemet and Komárek are speaking against a backdrop that's pretty grim.
3 / 15
What Researchers Are Being Asked to Do. The ask from Ledger and Trezor is pretty clear. Find a bug? Don't tweet it. Don't post a writeup.
4 / 15
Charles Guillemet is fed up. Ledger's CTO went public recently with a sharp critique aimed squarely at security researchers who rush to publish vulnerability findings before…
5 / 15
The timing matters. Artificial intelligence has made it dramatically easier to spot software bugs, which means the window between discovery and potential exploitation is…
6 / 15
Guillemet referenced a 90-day disclosure window as a kind of industry standard — the period vendors should get to address a reported vulnerability before researchers go public.
7 / 15
Jan Komárek from Trezor backed him up. Komárek's take is that the 90-day period isn't just a grace period handed to vendors — it's a mutual commitment.
8 / 15
It's a reasonable framework. And it's not new — coordinated disclosure has been a standard practice in enterprise cybersecurity for years.
9 / 15
Both Guillemet and Komárek are speaking against a backdrop that's pretty grim. Coldcard wallets have seen thefts exceeding $100 million.
10 / 15
Those two incidents alone make the case for why sloppy disclosure practices are genuinely costly. It's not hypothetical. The money is gone. The data is out there.
11 / 15
Hardware wallets are supposed to be the safest way to store crypto. They sit offline, away from exchange hacks and browser exploits.
12 / 15
Read also: Harmony Proposes Shutdown and Migration to Ethereum Following 109,000-Transaction Exploit
13 / 15
What Guillemet is pushing back against is the researcher who finds something, sits on it just long enough to write a dramatic blog post, and then drops it publicly with zero…
14 / 15
The AI angle makes it more urgent. Security researchers now have tools that can scan codebases and flag potential vulnerabilities at a speed that wasn't possible a few years ago.
15 / 15
Komárek's framing is worth sitting with. He wants researchers to see the 90-day window as a partnership, not a delay tactic.
The Currency Analytics
Want the full story?