Register and share your invite link to earn from video plays and referrals.

Charles Guillemet
@P3b7_
CTO at @ledger. Busy securing the blockchain revolution. Cryptography, (Hw) Security, Tech, Blockchain. Previously built the Donjon (@DonjonLedger)
Joined September 2018
303 Following    45.8K Followers
There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app. There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability research suite. It was fixed and deployed two weeks ago. If you keep your Ledger apps up to date, you are protected. That's the whole story. Now the framing. What actually happened: this company reached out to our bounty program after the fix was already shipped, and did not follow responsible disclosure, they actually never discussed with the bounty program team. Then they published a thread implying the problem is unsolved. It is not. That's not security research. That's manufacturing fear for attention. Here is the uncomfortable part. AI changes the security landscape for everyone, defenders and attackers alike. The @DonjonLedger is leading on exactly this: using AI to find real bugs before they reach users. But AI-speed research only makes the ecosystem safer if the people doing it still follow basic security principles. Disclose responsibly. Verify before you publish. Don't confuse noise with a finding. An actor who skips all of that is net negative for the ecosystem, regardless of the tooling behind them. The takeaway for you is simple. Keep your Ledger signers up to date (update the FW, update the apps), keep your software up to date in general, and you benefit from the latest security work automatically. Ignore the FUD. Stay safe.
Show more
0
66
588
107
Forward to community