Ledger and Trezor call for responsible disclosure of security vulnerabilities
2026-09-08 18:21:46
According to CoinMeta, Ledger and Trezor call on researchers to responsibly disclose their findings when vendors fail to fix vulnerabilities within the agreed disclosure timeframe. Charles Guillemet, the chief technology officer of Ledger, stated that artificial intelligence makes it easier to detect and exploit vulnerabilities, but some researchers release their findings before they are fixed, a practice he referred to as "cultivating attention at the expense of others." He urged researchers to report vulnerabilities privately and to agree on a fix timeline before releasing details. He mentioned that 90 days is a common default period, which depends on the severity of the vulnerability and the amount of work required to fix it. Jan Kom, the security responsible person at Trezor, also said, "90 days is a commitment made by vendors, not just by researchers."
Bullish 0
Bearish 0
Source:Cointelegraph
This content is for market information only and does not constitute investment advice.