Artificial intelligence is now making its way into the hunt for security vulnerabilities in hardware wallets — a trend that is raising serious concerns among manufacturers like Ledger and Trezor.
Ledger’s Chief Technology Officer is sounding the alarm: some researchers are using AI tools to uncover vulnerabilities, then making them public without any prior coordination with the affected teams.
Caught between ethical responsibility and the pursuit of visibility, the debate around responsible disclosure of crypto vulnerabilities is taking on a new dimension in the age of AI.
AI as a Bug Hunting Tool: A Double-Edged Sword
Artificial intelligence models have become formidable accelerators for code analysis. Security researchers are now using them to scan hardware wallet firmwares for vulnerabilities with unprecedented efficiency. But this power raises a fundamental question: what should you do with a flaw discovered in just a few hours using an LLM?
Charles Guillemet, CTO of Ledger, has taken a public stance on the issue. In his view, some researchers are giving in to what he calls “attention farming” — a practice that involves publishing vulnerability discoveries directly on social media or in public reports, without first contacting the relevant manufacturer. The goal: maximizing personal visibility at the expense of user security.
Trezor shares this concern. The two most widely used hardware wallet manufacturers in the world agree on one point: the race for notoriety must never take precedence over the protection of crypto asset holders. A vulnerability made public before it has been patched directly exposes users’ funds to malicious actors.
Responsible Disclosure: The Rules That AI Is Disrupting
The principle of coordinated disclosure — or “responsible disclosure” — is an established standard in the cybersecurity industry. It requires the researcher to notify the vendor first, allow a reasonable timeframe to fix the vulnerability (typically 90 days), and only then make their findings public if no action has been taken. This framework protects both users and the researcher’s own credibility.
Ledger and Trezor are clear that this protocol remains fully valid even when a discovery is AI-assisted. Guillemet notes that if a vendor fails to patch a vulnerability within the agreed timeframe, researchers then have the legitimacy — and even the responsibility — to publish their findings. Forced transparency becomes a tool for ethical pressure, not a personal branding exercise.
The problem is that AI compresses discovery timelines dramatically. An audit that would have taken a human expert several weeks can now be completed in a matter of hours. This acceleration places new pressure on manufacturers’ security teams, who must absorb a growing volume of reports — with quality and relevance varying considerably depending on whether the researcher genuinely understands the subject matter or is blindly relying on a model’s output.
When Wallet Security Becomes a Reputational Issue
For Ledger, the issue is particularly sensitive given that the company has already weathered major trust crises — most notably the customer data breach in 2020 and the controversy surrounding Ledger Recover in 2023. Every new public vulnerability disclosure, even a minor one, feeds a negative narrative that can erode user confidence in the security of cold wallets.
The hardware wallet market remains a cornerstone of financial sovereignty in crypto. With billions of dollars in self-custodied assets at stake, even the smallest unpatched vulnerability represents a real attack surface. The stakes go far beyond manufacturers’ reputations: it is the security of millions of users’ funds that is on the line.
The position taken by Ledger and Trezor sends a clear signal to the security research community: AI can be a powerful ally in vulnerability detection, but it does not exempt researchers from rigorous ethical conduct. Speed of discovery does not justify rushing to publish. In a sector where trust is the first line of defense, responsibility remains human — even when the tool is artificial.