Back

Responsible Disclosure in the Age of AI

Building a safer, more resilient Bitcoin ecosystem together.

AnchorWatch

September 7, 2026

In security, process matters as much as intent. Responsible disclosure exists to protect users while a vulnerability is investigated and fixed. Moving funds first and initiating a conversation afterward reverses that order and creates real risk, regardless of the label attached to it.

We’re co-signing Charles Guillemet’s post because the industry should hold a clear standard: protect users first, disclose responsibly, and allow the issue to be remediated before anyone is put at risk.

Read Post On X  

Responsible Disclosure in the Age of AI

AI made finding bugs cheap, but it didn’t make responsible disclosure optional.

Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers.

Which is exactly why the process around disclosure matters more than ever.

How it works, and it is not complicated:

  • A researcher finds a bug and contacts the vendor privately.
  • The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix...
  • During that window both sides keep it secret while the vendor fixes and ships.
  • Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid.

The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience:

  • ❗Presenting a reproduction of an already-fixed bug as a live compromise.
  • ❗Full disclosure of a bug that is not fixed yet.
  • ❗"Critical vulnerability found" teasers, dripping details for engagement.

Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem.

So I have three asks:

  1. For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more
  2. For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth.
  3. And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together.

Some of the actors already support the initiative.

@Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others

Spread the message.

- Charles Guillemet

Contact Us

Always here to help

To request general assistance, you should contact AnchorWatch Inc, at: