HACKER Q&A
📣 Translate2884

Hw crypto wallet manufacturer ignores bug reports, what to do?


Let's assume that a certain hardware crypto wallet with a seed recovery feature has a certain vulnerability in its USB stack which allows a certain researcher to exfiltrate the keys.

Let's assume that the manufacturer ignored any communications from said researcher.

What would be the right course of action?


  👤 aleph_minus_one Accepted Answer ✓
> What would be the right course of action?

Stop using the wallets of this vendor, and put a blog post on the internet at a place where it will get mirrored and thus be hard to delete, in which you document/disclose the details of the finding.