Ledger and Trezor call for responsible disclosure of security vulnerabilities amid AI threats
Hardware wallet competitors Ledger and Trezor unite to advocate for responsible security disclosure standards as artificial intelligence accelerates cryptographic attack risks. The push follows Ledger's discovery of a physical laser fault-injection vulnerability in the TROPIC01 chip used in Trezor Safe 7 wallets. Trezor confirms user funds remain secure due to its three-layer architecture, while both firms urge researchers to coordinate on a 90-day fix timeline before publishing flaws.
TROPIC01 chip vulnerability discovery
▪During the coordination process for the TROPIC01 chip vulnerability, manufacturer Tropic Square discovered an additional attack path affecting PIN-related functions.
▪The TROPIC01 chip vulnerability, which was publicly disclosed around June 3, 2026, requires physical possession of the device and specialized laboratory equipment to exploit.
▪Ledger's security research arm, Donjon, discovered a laser fault-injection vulnerability in the TROPIC01 chip manufactured by Tropic Square in late January 2026.
AI-accelerated cryptographic attack risks
▪Ledger chief technology officer Charles Guillemet stated that artificial intelligence tools make security bugs easier to find and exploit, compressing the timeline for real-world exploitation.
▪Ledger referenced an estimated $116 million theft incident involving Coldcard wallets in July 2026 as an example of entropy weaknesses meeting advanced attack tools.
▪Artificial intelligence tools can accelerate brute-force attacks against weak entropy in cryptographic key generation or PIN systems.
Responsible disclosure timeline standards
▪Trezor head of security Jan Komárek supported a 90-day default timeline for vulnerability fixes as a commitment for both vendors and researchers.
▪Ledger chief technology officer Charles Guillemet criticized researchers who publish security findings before fixes are available, calling the practice "attention farming with someone else's risk."
▪Ledger chief technology officer Charles Guillemet urged security researchers to report bugs privately and agree on a timeline for fixes before publishing details.
Trezor Safe 7 layered architecture
▪Trezor assured users that funds remain safe because the Trezor Safe 7 wallet utilizes three independent security layers to protect user assets.
▪The three-layer architecture of the Trezor Safe 7 wallet prevents a compromised TROPIC01 chip from exposing user cryptocurrency assets.
Ledger-Trezor cross-company security cooperation
▪Ledger and Trezor previously coordinated the disclosure of a voltage-glitch vulnerability in hardware wallets in 2025.
▪Trezor CEO Matej Žák framed the collaborative disclosure of the TROPIC01 chip vulnerability as a model for the hardware wallet industry.
▪Competitors Ledger and Trezor have a history of cooperative security disclosures dating back to early-generation hardware wallet flaws identified in 2018-2019.
Story comments
Loading comments…