Ledger, Trezor call for standardized vulnerability disclosure

In Crypto Regulations
September 08, 2026

Ledger, Trezor call for standardized vulnerability disclosure

On September 7, Ledger CTO Charles Guillemet published an open letter proposing to make coordinated vulnerability disclosure an industry norm. The initiative was supported by Trezor, Foundation, AnchorWatch, SEAL and other market participants.

“AI made finding vulnerabilities cheap, but it didn’t make responsible disclosure optional,” the post says.

Guillemet outlined a four-step coordinated disclosure process: the researcher confidentially reports a vulnerability to the company; the team reproduces the issue, confirms it, and agrees on a remediation timeline with the reporter.

    As a baseline, the Ledger CTO proposed 90 days, although the period may vary depending on the severity of the bug and the complexity of the patch. During remediation, neither side publishes technical details. After the update is released, information is fully disclosed, and the researcher typically receives a reward.

    Guillemet said the spread of AI makes this approach especially important. The low barrier to entry enables people without security experience to find real bugs, but some immediately publish their findings on social media.

    “Security is still a cat-and-mouse game, but with many more cats, and users suffer,” he emphasized.

    He highlighted three problematic scenarios:

    • reproducing an already fixed bug and presenting it as a live attack;
    • full disclosure of a vulnerability before a patch is available;
    • teaser posts like “a critical vulnerability was found,” with gradual detail release for attention.

    “Call it what it is: chasing attention at someone else’s risk,” the expert wrote.

    He called this practice particularly dangerous for the cryptocurrency industry, where a mistaken transaction is usually irreversible.

    Three calls to users and researchers

    Guillemet’s first call was to users: install firmware and app updates promptly. According to him, language models have shortened the window between a fix being published and tools to exploit the old bug appearing, making it riskier to delay upgrades.

    The second call concerns new researchers using artificial intelligence to find vulnerabilities. Guillemet suggested submitting confirmed findings through vendors’ official disclosure programs. In subsequent publications, he urged researchers to state the severity, affected product versions, and whether a fix is available.

    “This isn’t bureaucracy. It’s the difference between improving ecosystem security and creating risk for users for a few likes,” the Ledger CTO said.

    The third call was to companies and security professionals. Guillemet proposed publicly supporting coordinated disclosure, rewarding researchers who follow it, and avoiding amplification of publications that prioritize reach over user safety.

    Trezor’s response

    In a comment to ForkLog, Trezor head of security Jan Komarek emphasized that finding new issues does not by itself mean a security failure.

    “Security is not a state you can achieve once and keep. It’s a continuous cycle: researchers find issues, manufacturers fix them, users update software, and the system becomes more reliable,” he explained.

    According to Komarek, this process breaks down when technical details are published before a fix is available or when an already resolved bug is presented as active.

    In the cryptocurrency industry, the consequences can extend beyond the vulnerability itself. Scammers can exploit the panic for phishing and impersonate support, urging users to “move funds to a safe place.”

    “Secondary damage regularly turns out to be more serious than what the bug itself could cause,” Komarek noted.

    He also supported the 90-day baseline, calling it a commitment not only for the researcher but also for the vendor. In his view, if a company fails to fix the issue within the agreed timeframe, the researcher should have the right to publish technical details.

    Komarek separately linked the discussion to the incident in the Bitcoin sidechain Liquid Network. On September 6, unknown individuals who called themselves white-hat hackers withdrew about 4,000 BTC worth roughly $320 million from the Liquid federation wallet.

    According to the SideSwap team, the service received 4,000 L-BTC. The tokens were destroyed as part of the standard redemption procedure, after which the federation paid out 3,996 BTC.

    SideSwap claims that in the subsequent investigation, Blockstream specialists discovered a bug in the Elements software that allowed creating L-BTC without corresponding bitcoin backing.

    Participants in the incident said they would return most of the funds after the bug is fixed and the network’s nodes are updated. Blockstream later sent them a signed message stating the upgrade was complete and that it was ready to accept the assets back.

    “This violates the principles of responsible disclosure,” Komarek commented.

    Debate over disclosure

    In late August, coordinated disclosure had already become a point of contention around Ledger. On August 22, AI security company TestMachine publicly described a vulnerability in Ledger’s Ethereum app.

    The next day, Guillemet said the Ledger Donjon team discovered the issue independently and fixed it before TestMachine’s publication. According to him, the researchers submitted to the bug bounty program after the patch had been released and did not coordinate public disclosure with Ledger.

    On August 27, the OneKey Anzen team reproduced the attack in the lab on Ledger’s Ethereum app version 1.22.1. Due to a race condition, the device could, under certain conditions, display one operation while signing another.

    According to Ledger’s bulletin, the Ethereum app version 1.22.2 with the fix was released on August 13. On August 21, the company also eliminated the possibility of such an attack at the Ledger Secure SDK level.

    In August, hardware wallet makers Trezor and Foundation warned users about phishing attacks amid the Coldcard incident.

    Avatar photo
    / Published posts: 1045

    Steven M. Crimmins is a cryptocurrency strategist and freelance writer who has followed the blockchain industry since Bitcoin’s early days. Known for his sharp analysis of altcoins and trading strategies, Steven provides Satoshi News Africa readers with market-focused content grounded in research. He is especially interested in how African traders are adopting crypto as an alternative to traditional markets. Steven is also a podcast host, where he discusses emerging technologies and investment trends.