The crypto industry has long been plagued by hacking incidents and exploits, but the situation is now being exacerbated by artificial intelligence, according to Charles Guillemet, chief technology officer at Ledger. Guillemet notes that AI tools are making it faster and more affordable for hackers to attack systems, thereby breaking down the economics of cybersecurity. "Identifying and exploiting vulnerabilities has become extremely easy," Guillemet stated in an interview.
"The cost is essentially zero." His comments come amid a string of high-profile crypto heists, including the recent $285 million exploit of Solana-based protocol Drift and the $25 million attack on yield protocol Resolv. Over the past year, crypto attacks have resulted in the theft or loss of over $1.4 billion in assets, according to data from DefiLlama. The traditional security imbalance, where it is more difficult and expensive to hack a system than the potential reward, is being eroded by AI. Tasks that once required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts.
For crypto, where code often controls large pools of funds, this shift raises the stakes. "You need to be perfect," Guillemet warned teams developing blockchain protocols. The problem is further complicated by AI-generated code, which can spread vulnerabilities more quickly. "There is no 'make it secure' button," he said.
"We will produce a lot of code that is insecure by design." To address this issue, Guillemet suggests that crypto protocols need to rethink security from the ground up. He recommends using formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits. Hardware-based security is another layer, he said, with devices like hardware wallets isolating private keys from internet-connected systems and reducing exposure.
"When you have a dedicated device not exposed to the internet, it is more secure by design," he said. As malware becomes more advanced, this approach is becoming increasingly relevant. Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction.
For average crypto users, Guillemet's message is clear: assume that systems can and will fail. "You can’t trust most of the systems that you use," Guillemet said. This could lead to more users adopting cold storage, strengthening operational security, and keeping sensitive data offline.
However, even then, risks extend beyond software, including physical attacks targeting crypto holders. Guillemet expects a divide ahead, with critical systems like wallets and protocols investing heavily in security and adapting, while much of the broader software ecosystem may struggle to keep up. "It’s really easier to hack everything," he said.