Ledger and Trezor state that if a vendor fails to fix a vulnerability within the agreed-upon disclosure window, researchers have a responsibility to publish their findings.