Switching hardware wallets? Migrate to Ledger safely in a few steps.

Learn more

Thought leadership | 09/11/2026

AI Made Finding Bugs Cheap. But Disclosure Isn’t Optional

AI hasn't just lowered the cost of attacks. It lowered the cost of finding vulnerabilities for everyone. That changes what responsible disclosure means in practice, and raises the stakes for getting it wrong.

Before You Dive In:

  • AI has collapsed the cost of vulnerability research. More bugs will surface faster, found by more people with less security experience than ever before.
  • Zerodayclock.com estimates reported vulnerabilities in just the first half of 2026 as 4x higher than the whole of 2018
  • That acceleration makes coordinated disclosure that much more critical. The window between a fix shipping and an attacker weaponizing a patch has shrunk from months to weeks.
  • There is a right way and a wrong way to handle a finding, and it has direct consequences for users.

The New Economics of Security

In a previous post, I argued that AI is dismantling the economic asymmetry that security has depended on for decades. The cost of finding vulnerabilities is dropping toward zero. Systems that were “secure enough” because attacking them was uneconomical are now exposed.

But there is a second implication I did not address directly, and it is becoming harder to ignore.

If AI makes finding bugs cheap for defenders, it makes finding bugs cheap for everyone. Security researchers, red teams, hobbyists, and attackers are all working from the same expanding toolkit. The practical result is that more findings will emerge, from more directions, at a pace the industry has never had to manage before. 

Zerodayclock.com maps registered vulnerability and exploitation growth. In HI of 2026 there were 35,853 vulnerabilities published compared to 8,547 in the whole of 2018, with 485 vs 51 newly named as exploited across those time periods – a dramatic change in scale.

Image Credit: Zerodayclock.com

That changes what responsible disclosure actually means. It used to be a professional norm observed by a relatively small group of trained researchers who understood the stakes. That group is now much larger, much less uniform, and operating in an environment where the distance between a finding and a working exploit has compressed dramatically.

The process around disclosure was critically important before. Now it is load-bearing.

The New Defensive Playbook Already Exists

On May 29, 2026, security researcher Taylor Hornby was conducting an ongoing protocol review for Shielded Labs using a custom AI auditing framework paired with a frontier model. He found a critical flaw in Zcash’s Orchard shielded pool. Two lines of code in the halo2 gadget left an elliptic curve multiplication check under-constrained. 

The consequence: anyone who understood the circuit could have minted ZEC out of thin air, silently, with no on-chain signature. The bug had been live since Orchard’s activation in May 2022. For four years, it went undetected by some of the best cryptographers in the ecosystem. The fix shipped via coordinated soft fork on June 2-3, and the full disclosure followed shortly after.

What happened next is worth examining in detail. The finding went to the Zcash team privately. A soft fork disabling the Orchard pool was prepared and distributed without leaking the vulnerability. It activated roughly two and a half days after acknowledgement. Coordinating a network upgrade across miners, exchanges, and nodes without disclosing why is genuinely difficult. They did it. Then they published: timeline, code lines, the math, and open questions. No spin.

No user funds were lost. No exploit in the wild was ever confirmed. The Zcash Foundation later announced plans to formally verify the Orchard circuit as a direct result of the incident.

This is the template for how responsible disclosure can look in the future. AI finds the bug while users remain protected.

Disclosure Without Coordination Is Not Research

Not every actor follows the same model.

The pattern that is emerging with AI-assisted research is this: a researcher, or increasingly a company with a commercial interest in the finding, surfaces a vulnerability and goes straight to the audience. Sometimes it is a real bug in an unpatched system, disclosed publicly before the vendor has any chance to fix it. Sometimes it is a reproduction of an already-fixed bug, presented as a live compromise. Sometimes it is a “critical vulnerability found” teaser, dripping detail for engagement while users have no idea whether they are at risk.

Call it for what it is: attention farming with someone else’s risk.

This approach carries real problems. When a user panics and moves funds under a false impression of active threat, they bear that risk alone. And manufactured panic does damage that does not require live funds to be at stake. At best, it can drive people away from self-custody, eroding trust in the tools that are actually protecting them. That damage goes beyond the single vendor being targeted and lands on the entire ecosystem.

There is a particular irony in a security researcher causing harm in the name of transparency. Responsible disclosure exists precisely because the security community understood, decades ago, that the timing of information matters as much as the information itself. 

When a bug can be found in hours rather than weeks, the gap between discovery and weaponization collapses dramatically. A bug disclosed before a patch is a gift to every attacker who reads the thread and agents will be scanning for these opportunities at machine speed. A bug disclosed after a patch is a lesson the ecosystem can learn from safely. AI has only made ignoring that logic more dangerous.

Where Responsible Disclosure Goes From Here

1. For Users 

Software and hardware have bugs. They always have, and they always will. The single most effective thing you can do is stay updated and treat security hygiene as active maintenance, not a one-time setup. The time between a patch shipping and attackers reverse-engineering it to find the vulnerability has collapsed. Postponing updates is no longer a low-risk habit. It is meaningful exposure to additional risk.

You can always find and download the latest version of Ledger Wallet™ here.

2. For New Researchers with A Real, Validated Finding

Welcome. The ecosystem needs you. Use the vendor’s disclosure process. That is not bureaucracy, and it is not a way for companies to bury findings. It is the mechanism that gives users time to be protected before the vulnerability becomes public knowledge. Security communication must be accurate and proportionate: state the severity, the affected versions, and the fix status clearly, early, and honestly. The researchers who do this well are the ones who make the ecosystem genuinely safer.

Ledger supports responsible disclosure of any vulnerabilities regarding its ecosystem through the Ledger Donjon Bug Bounty Program.

3. For Builders, Vendors & Researchers 

Make coordinated disclosure the norm you defend out loud, not fine print buried in a bounty program policy. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is not idealism. It is the only model that scales when the volume of findings is growing this fast.

Spread the message.


Charles Guillemet, Ledger CTO

Stay in touch

Announcements can be found in our blog. Press contact:
[email protected]

Subscribe to our
newsletter

New coins supported, blog updates and exclusive offers directly in your inbox


Your email address will only be used to send you our newsletter, as well as updates and offers. You can unsubscribe at any time using the link included in the newsletter. Learn more about how we manage your data and your rights.