Key Takeaways

  • AI is accelerating bug discovery, but researchers still need to follow responsible disclosure practices.

  • Charles Guillemet recommended private reporting and a 90-day fix window before vulnerability details are made public.

  • Premature disclosures can put users at risk of theft, scams, and unnecessary panic.

AI Changes the Security Game

Ledger Chief Technology Officer Charles Guillemet has questioned whether the people behind the recent withdrawal of about 4,000 BTC from the Liquid Network should really be called “white hat” hackers.

The Bitcoin was worth roughly $320 million at the time. The incident has also started a wider discussion about how security researchers should report vulnerabilities in the digital asset industry.

Liquid is a Bitcoin sidechain that allows users to move bitcoin into the network and receive an equivalent amount of Liquid Bitcoin, or L-BTC. The L-BTC can later be exchanged back for bitcoin.

On September 6, about 4,000 BTC left the Liquid Federation wallet. According to SideSwap, 4,000 L-BTC was sent to its peg-out service, and the federation then paid out 3,996 BTC.

The Ledger executive compared the incident with previous major digital asset attacks and said the behavior did not look like normal white-hat security research.

However, he also said that the people involved might not have intended to steal the funds permanently.

“There’s hope. This could be people with good intentions that intensively played with recent LLMs and are not used to responsible disclosures,” Guillemet wrote.

For Guillemet, however, the bigger issue is how security vulnerabilities are reported. In his statement, Guillemet called for coordinated vulnerability disclosure to become a standard practice across the industry.

His argument is simple: artificial intelligence has made it much easier to find bugs, but that does not mean researchers should immediately publish what they find.

“AI made finding bugs cheap, but it didn’t make responsible disclosure optional,” Guillemet wrote. He suggested a basic process.

First, a researcher privately reports the vulnerability to the company. The company then checks the problem and works with the researcher on a deadline for fixing it.

Guillemet suggested 90 days as a normal starting point, although the deadline could be shorter or longer depending on the problem.

During that period, the details remain private while the company works on a fix. Once the fix is released and users are protected, the researcher and company can publish the details.

Guillemet also criticized researchers who publish information about vulnerabilities mainly to attract attention.

He pointed to cases where people present an already-fixed bug as if it were still active, reveal an unfixed vulnerability publicly, or post vague warnings about a “critical vulnerability” without giving users enough useful information.

“Call it what it is: attention farming with someone else’s risk,” he wrote. This can be particularly dangerous in digital assets because Bitcoin transactions generally cannot be reversed.

Trezor Head of Security Jan Komárek also supports the approach. In an email to Bitcoin News, Komárek said that finding a vulnerability does not automatically mean a product or company has failed.

Security, he explained, is an ongoing process in which researchers find problems, companies fix them and users update their software.

“Security isn't a state you reach and then hold. It's a cycle you run continuously: researchers find things, vendors fix them, users update, and the system comes out stronger,” Komárek said.

He warned that problems arise when researchers publish details before a fix is available.

In Bitcoin, there is another risk: scammers can use security news to create panic and trick users. For example, attackers may pretend to be customer support and tell people to move their coins to a supposedly “safe” wallet.

“The secondary damage routinely exceeds anything the original bug could have caused,” Komárek said.

He also agreed with the 90-day disclosure period but stressed that companies have a responsibility to meet the deadline.

“Ninety days is a commitment on the vendor, not just on the researcher,” he said. He also gave a direct assessment of the Liquid incident, saying it “violates the principles of responsible disclosure.”

The Liquid incident has therefore become part of a broader debate about security research in Bitcoin and the broader digital asset industry.

AI is making it easier and faster to find software bugs. That can be good for security because more vulnerabilities can be discovered and fixed. But Guillemet and Komárek argue that finding a bug is only the first step. How the vulnerability is reported can determine whether users are protected or exposed.

Their message to researchers is to report serious bugs privately first. Their message to companies is to fix them within an agreed timeframe. And their message to users is simple: keep wallets, apps and firmware updated.

100% of the sats go directly to the author

Latest on YouTube


Reply

Avatar

or to participate