Ledger just handed one person the keys to both its technology kingdom and its security fortress. The Paris-based hardware wallet maker appointed Oded Blatman as its combined chief information officer and chief security officer on September 9, 2026, merging two traditionally separate leadership roles into a single, unified command structure.
The threat landscape that forced the move
The crypto industry has hemorrhaged $1.4 billion from hacks and exploits over the past year. That figure, cited by Ledger CTO Charles Guillemet, represents not just sloppy code or lazy key management. It reflects a fundamental shift in how attackers operate.
AI-generated phishing campaigns have grown disturbingly sophisticated. Autonomous attack systems can probe infrastructure around the clock, identifying and exploiting vulnerabilities faster than most security teams can patch them.
Blatman arrives from Fireblocks, the institutional crypto infrastructure company, where he served as CIO and CISO. His new role at Ledger is notably broader. He’ll oversee cyber and infrastructure security, product security (including Ledger’s in-house research team, the Donjon), physical security, enterprise risk management, and internal IT.
Ledger’s 2026 AI security playbook
The company rolled out an AI security roadmap back in April that includes a “Proof of Human” security protocol slated for the fourth quarter of 2026, designed to verify that a human, not an AI agent or deepfake, is actually initiating a transaction or security-sensitive action.
On September 4, just days before the Blatman announcement, the company released Cerberus, an AI-powered vulnerability detection system designed to continuously scan for security weaknesses before attackers can exploit them.
In July, Ledger also launched its open-source Ledger Agent Stack.
An industry circling the wagons
Two days before naming Blatman, on September 7, Ledger and rival hardware wallet maker Trezor jointly called for responsible vulnerability disclosure standards on critical flaws. Responsible disclosure means that when a researcher finds a critical vulnerability, they notify the affected company privately and give them time to fix it before going public.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

3 hours ago
23







English (US) ·