Ledger and Trezor Unite Against AI-Driven Threats: Emphasizing Responsible Disclosure
Two major players in the crypto hardware wallet market, Ledger and Trezor, have demonstrated unprecedented cooperation to enhance security. Donjon, Ledger's security research arm, discovered a vulnerability in the TROPIC01 chip used by Trezor's Safe 7 wallet. The flaw allows for laser fault-injection attacks, but it requires physical possession of the device and specialized equipment.
The vulnerability was publicly disclosed after Ledger coordinated with Tropic Square, the manufacturer of the chip. This collaboration uncovered an additional attack path affecting PIN-related functions, resulting in more security insights than either party could have found alone.
Trezor reassured users that their funds and backups remain safe due to the Safe 7's design architecture, which includes three independent security layers protecting user assets.
The companies are now advocating for industry-wide standards on how security flaws get reported. They warn that advances in artificial intelligence have compressed the timeline between vulnerability discovery and real-world exploitation, making it essential for manufacturers to disclose vulnerabilities responsibly.