Let's assume that the manufacturer ignored any communications from said researcher.
What would be the right course of action?
Stop using the wallets of this vendor, and put a blog post on the internet at a place where it will get mirrored and thus be hard to delete, in which you document/disclose the details of the finding.