UPDATED SEPTEMBER 16, 2026
UPDATED SEPTEMBER 16, 2026

The Frontier

Your signal. Your price.

Include
Lookback
||
  • · 1d ago

    The four-year lifespan of the Cold Card random number generator bug highlights a massive resource disparity in hardware security. Jameson Lopp points out that Cold Card operates with only two or three engineers, compared to Ledger's team of approximately 100.

    +3 more
    +3 more
  • · 8d ago

    Ledger CTO Charles Gilmette argues that artificial intelligence has simplified bug discovery, prompting some researchers to publish vulnerabilities prematurely to gain attention. Gilmette and Trezor security head Jan Komarek advocate for a standard 90-day private disclosure window to develop patches.

    +3 more
    +4 more
  • · 27d ago

    Open Ledger's Ram Kumar argues that AI agents will drive cryptocurrency adoption because they cannot pass traditional identity checks or open bank accounts. David Bennett disputes this, predicting banks will rapidly develop compliant protocols to capture agentic financial flows.

    +3 more
    +3 more
  • · 6w ago

    Ledger CTO Charles Guillemet argues the exploit proves open-source code is not inherently secure, as an attacker reportedly used AI to locate the long-standing bug. Guillemet advocates for hardware-level, independently certified randomness rather than software fallbacks.

    +3 more
    +2 more
  • · 6w ago

    Rob Hamilton recommends moving funds to trusted exchanges like River, citing its in-house custody and proof of reserves, or immediately acquiring other hardware wallets like Ledger or BitKey as emergency measures.

    +3 more
    +4 more
  • · 6w ago

    Past incidents include Ledger spilling client data multiple times and BitBox having physical defects allowing key exfiltration, underscoring the inherent difficulty of hardware wallet security.

    +2 more
    +2 more
  • · 2mo ago

    Ledger released an open-source AI Agent Stack requiring a Ledger hardware device to approve transactions, aiming to secure AI interactions with wallets.

    +2 more
    +2 more
  • · 2mo ago

    David Bennett warns against Ledger due to repeated customer data hacks, forced firmware updates for forks, and the risk of requiring their hardware for AI agents.

    +4 more
    +2 more
  • · 2mo ago

    Matt noted that CoinKite, which deletes customer data after 120 days, suspects the scam letters originated from aggregated data leaks or shipping company compromises, citing identical signatures across scam letters from Ledger and CoinKite.

    +3 more
    +2 more
  • · 2mo ago

    Woodhouse stresses the need for battle testing custody setups. He recounts a case where a Ledger in a 2-of-3 multisig died, temporarily reducing the setup to 2-of-2 and creating a vulnerability.

    +1 more
    +1 more
About The Frontier
End of 90-day results — 10 results
10 results