Ledger CTO urges AI bug hunter responsibility, warns against ‘attention farming’

Lời nói đầu:Ledger and Trezor urged researchers to report bugs privately and give vendors time to fix them as AI makes vulnerabilities easier to find and exploit.

Hardware wallet makers Ledger and Trezor called for more responsible disclosure of security vulnerabilities.

In a Monday post on X, Ledger chief technology officer Charles Guillemet said artificial intelligence has made bugs easier to find and exploit. However, some researchers are publishing their findings before fixes are available, a practice he called “attention farming with someone elses risk.”

Guillemet urged researchers to report bugs privately and agree on a timeline for fixes before publishing details. He cited 90 days as a common default, with flexibility depending on the severity of the flaw and the work needed to fix it.

“Ninety days is a commitment on the vendor, not just on the researcher,” Jan Komárek, Trezors head of security, told Cointelegraph.

“Researchers: come to us first, agree a timeline, then publish in full, and if we fail to ship a fix in that window, publish anyway,” he said.

Hardware wallet security has come under scrutiny after Coldcard thefts exceeded $100 million and a data breach at Trezor‘s shipping provider exposed tens of thousands of customers’ personal information.

Miễn trừ trách nhiệm

Các ý kiến ​​trong bài viết này chỉ thể hiện quan điểm cá nhân của tác giả và không phải lời khuyên đầu tư. Thông tin trong bài viết mang tính tham khảo và không đảm bảo tính chính xác tuyệt đối. Nền tảng không chịu trách nhiệm cho bất kỳ quyết định đầu tư nào được đưa ra dựa trên nội dung này.
Bài viết trước

Chuỗi Robinhood có thể tạo ra 160 triệu USD phí hằng năm vào năm 2028: Bernstein

Bài tiếp theo

Uzbekistan bắt đầu thí điểm thanh toán bằng stablecoin được bảo chứng bằng trái phiếu chính phủ