The stakes are hard to overstate. A single unpatched flaw in a device holding private keys can drain wallets. That is why both vendors lean on coordinated vulnerability disclosure, the practice of quietly reporting a bug, letting the vendor patch it, and only then telling the public. For related coverage, see AINext Awards & Conference Dubai 2026: Where AI Leaders, Innovators and Decision-Makers Shape the Future of Artificial Intelligence.
Ledger and Trezor call for responsible disclosure
Ledger asks researchers to give it the opportunity to diagnose and remedy vulnerabilities before disclosing details to third parties or the public, according to its Donjon bug-bounty policy. The company frames coordinated disclosure as the responsible default, not an optional courtesy. For related coverage, see AgriNext Awards & Conference Dubai 2026: Where Agriculture Leaders, Innovators and Investors Shape the Future of Food Systems.
Ledger has said as much in plain terms.
“At Ledger, we believe that Coordinated Vulnerability Disclosure is the right approach to better protect users.”
Trezor takes a parallel line. Its security portal asks bug-bounty researchers to act in good faith, to give the company time to fix an issue before public disclosure, and to avoid fraud or harm, per its published security terms. For related coverage, see Nearly 4,000 BTC Leave Liquid Through Valid Peg-Out.
Two competitors, one philosophy. Neither wants a flaw dumped on the open internet before there is a patch ready to ship. This is a standing policy stance, not a confirmed joint announcement or a response to any specific breach. For related coverage, see Liquid Network Releases 3,996 BTC After L-BTC Burn.
The disclosure debate is not academic for Ledger. The company has faced scrutiny before, including a case where an Ethereum app was patched before an exploit could hit users, exactly the kind of outcome coordinated disclosure is built to produce.
What responsible disclosure means for security vulnerabilities
The model is simple in theory. A researcher finds a flaw, reports it privately, the vendor assesses and fixes it, and disclosure follows once users are protected. The friction lives in the timing.
Ledger puts a number on it. Its 90-day disclosure policy means the company does its best to fix issues within 90 days of receiving a vulnerability report, though it stresses this is a target, not a guaranteed deadline.
Ledger’s best-effort remediation target
90 days
Ledger also draws a hard line on quality. It does not accept reports generated entirely or primarily by automated tools or AI without meaningful human analysis, demanding that submissions show understanding of root cause and impact and include a valid proof of concept or clear reproduction steps.
Trezor sets a similar bar. Its reports must include proof-of-concept code and a thorough description of the bug and its potential impact, a requirement meant to weed out noise and prove a flaw is real.
There is money behind the ask. Trezor lists critical-vulnerability rewards ranging from $1,000 to $100,000, with an explicit note that exceptionally disastrous cases carry no upper limit, though severity and eligibility stay at its discretion.
This private-sector approach echoes government thinking. The U.S. Cybersecurity and Infrastructure Security Agency published BOD 20-01 on September 2, 2020, requiring covered federal agencies to develop and publish vulnerability disclosure policies and maintain handling procedures.
Crucially, that directive says agency policies must not restrict researchers’ disclosure except through a request for a reasonably time-limited response period. It also separates disclosure policies from paid bounties and does not mandate a bounty program. The scope is federal agencies, not private wallet makers, so it is context, not a rule imposed on Ledger or Trezor.
What the disclosure call means for Ledger and Trezor users
Here is what a disclosure appeal does not mean: it does not confirm that any user has been compromised, that funds are at risk, or that a specific product is vulnerable. The policies name no affected products, versions, or losses.
Reports that AI is driving a fresh wave of wallet threats remain, for now, unconfirmed. The idea that Ledger and Trezor issued a new appeal tied specifically to AI security threats comes from a single account that could not be independently verified, and no incident counts or loss figures back it.
What is solid is the process. If you use either device, the practical takeaway is that both companies want flaws handled quietly and fixed before disclosure, which reduces the odds that a bug becomes public before a patch exists.
So the real question hanging over hardware wallets is not whether bugs exist. They always will. It is whether the researchers who find them next choose the 90-day handshake, or the headline.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.