The crypto industry has long been plagued by cyber attacks and security breaches. However, the emergence of artificial intelligence (AI) has significantly exacerbated this problem. Charles Guillemet, chief technology officer at Ledger, a prominent crypto wallet provider, asserts that the economic model of cybersecurity is disintegrating as AI-powered tools render it faster and more affordable to launch attacks on systems.

Guillemet noted in an interview that "identifying and exploiting vulnerabilities has become remarkably easy" and that "the cost is essentially zero." His comments come amidst a surge in high-profile crypto heists, including the recent $285 million exploit of Solana-based decentralized finance protocol Drift and the $25 million attack on yield protocol Resolv. According to data from DefiLlama, over $1.4 billion in assets were stolen or lost due to crypto attacks in the past year. The traditional security paradigm, which relies on the imbalance between the cost of hacking and the potential reward, is being eroded by AI. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts.

For the crypto industry, where code often controls vast sums of money, this shift significantly raises the stakes. Guillemet cautioned teams developing blockchain protocols that "you need to be perfect." The issue is further complicated by AI-generated code, which can rapidly disseminate vulnerabilities as more developers rely on AI tools. Guillemet emphasized that "there is no 'make it secure' button" and that "we are going to produce a lot of code that will be insecure by design." To address this challenge, crypto protocols must rethink security from the ground up.

Guillemet advocated for formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits. He also highlighted the importance of hardware-based security, such as devices that isolate private keys from internet-connected systems, reducing exposure. For average crypto users, Guillemet's message is clear: assume that systems can and will fail.

He advised users to adopt a more cautious approach, including the use of cold storage, robust operational security, and keeping sensitive data offline. Despite these precautions, risks still exist, including physical attacks targeting crypto holders. Guillemet anticipates a divide in the future, with critical systems like wallets and protocols investing heavily in security and adapting, while much of the broader software ecosystem may struggle to keep up.

Ultimately, he warned that "it's really easier to hack everything."