Ledger and Trezor Call for Responsible Disclosure in the AI Era
Hardware wallet makers Ledger and Trezor used the week's incidents to call for stricter vulnerability disclosure norms, arguing that AI has changed the economics of bug hunting faster than etiquette has caught up.
In a post on X, Ledger CTO Charles Guillemet said AI has made bugs easier to find and exploit — but that some researchers now publish findings before fixes are available, a practice he called "attention farming with someone else's risk." He urged researchers to report bugs privately and agree on a fix timeline before publishing, citing 90 days as a common default with flexibility for severity and remediation effort.
Trezor's head of security, Jan Komárek, went further on where the obligation sits: "Ninety days is a commitment on the vendor, not just on the researcher," he said, adding: "Researchers: come to us first, agree a timeline, then publish in full, and if we fail to ship a fix in that window, publish anyway."
The timing is not accidental. Hardware wallet security has spent weeks in the headlines — Coldcard thefts exceeding $100 million from a firmware flaw, and a data breach at Trezor's shipping provider exposing tens of thousands of customers. Both companies are asking the research community to treat disclosure as infrastructure, not content.
Coldcard Exploiter Moves $7.7M — Nearly Half the Wave-3 Haul
The attacker behind the third wave of Coldcard thefts has moved 97.09 BTC, roughly $7.7 million and about 45% of that wave's haul, according to Galaxy Research's on-chain tracking.
The first exit came on September 2, when around 20.5 BTC from the largest vault crossed THORChain and emerged on Ethereum. Funds moved Sunday night went into CoinJoin rounds instead — with only 20.56 BTC actually reaching Ethereum, 57.24 BTC sitting unspent as CoinJoin change in a single address, and the trail ending on roughly 19 BTC more.
Galaxy's mapping shows the wave-3 vaults as the attacker's own construction: 293 two-of-two multisig addresses worked through in order of size, eleven now empty. Across the whole Coldcard exploit, 82% of the stolen Bitcoin has still not moved. Galaxy also flagged a previously unknown vault fed by 58 addresses whose cause remains open — if it proves to be another Coldcard victim, the published total would rise to about 1,806 BTC, or roughly $143.9 million.
The root cause is unchanged: a firmware bug introduced in March 2021 that rerouted seed generation off the hardware RNG and onto a software fallback, collapsing key strength from 128 bits of entropy to as low as 40. Updated firmware cannot repair seeds generated under the flawed version — affected owners must generate a fresh seed and move their coins.
Poland Detains Fifth Suspect in Zondacrypto Probe
A court in Katowice has approved pretrial detention for a fifth suspect in the Zondacrypto investigation, Prosecutor General Waldemar Żurek announced late Monday.
The suspect, named under Poland's convention as Roman Ż., was charged with membership in an organized criminal group and with misappropriating clients' funds through computer fraud — specifically, unauthorized changes, deletions, and additions to exchange data, and interference with how the exchange processed and transmitted it. Prosecutors put the alleged misappropriation at no less than 7.8 million złoty (around $2 million). He faces up to ten years if convicted, denied the charges, and was detained in Silesia on Saturday along with a seizure of exchange documents.
Three other suspects — Anna P., Jaromira W., and Rafał Z. — were placed in three-month pretrial detention on September 4 over what prosecutors describe as a plot to take control of founder Sylwester Suszek's assets. The wider case now spans an alleged €8 million property purchase in France, a €2.9 million loan falsely recorded as repaid, and 7.5 million złoty laundered through fictitious property deals. The exchange, which claimed 1.3 million clients, froze withdrawals and went dark in April; its post-Suszek CEO has not been seen since April 16. Estonia's financial intelligence unit revoked the operator's license in June.
All charges remain allegations pending trial.
TrustGrade tracks the security posture of wallet vendors, protocols, and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.