Building a safer, more resilient Bitcoin ecosystem together.
AnchorWatch
September 7, 2026
In security, process matters as much as intent. Responsible disclosure exists to protect users while a vulnerability is investigated and fixed. Moving funds first and initiating a conversation afterward reverses that order and creates real risk, regardless of the label attached to it.
We’re co-signing Charles Guillemet’s post because the industry should hold a clear standard: protect users first, disclose responsibly, and allow the issue to be remediated before anyone is put at risk.
AI made finding bugs cheap, but it didn’t make responsible disclosure optional.
Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers.
Which is exactly why the process around disclosure matters more than ever.
How it works, and it is not complicated:
A researcher finds a bug and contacts the vendor privately.
The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix...
During that window both sides keep it secret while the vendor fixes and ships.
Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid.
The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience:
❗Presenting a reproduction of an already-fixed bug as a live compromise.
❗Full disclosure of a bug that is not fixed yet.
❗"Critical vulnerability found" teasers, dripping details for engagement.
Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem.
So I have three asks:
For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more
For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth.
And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together.
Some of the actors already support the initiative.
To make an initial complaint, you should contact Arch Insurance at: The Complaints Manager Email: Complaints@archinsurance.com Arch Insurance (UK) Limited 4th Floor 10 Fenchurch Avenue London EC3M 5BN United Kingdom
In the alternative, you may wish to contact the Lloyd’s Complaints Department at:
Lloyd’s Complaints Department c/o Email: complaints@lloyds.comLloyd’s Phone: 1-844-849-7828 America Inc. 280 Park Avenue, East Tower, 25th Floor, New York, NY 10017, USA