The cryptocurrency landscape has long been plagued by hacking incidents and exploits, and now, artificial intelligence is exacerbating the problem. Ledger's Chief Technology Officer, Charles Guillemet, believes that the economic foundations of cybersecurity are crumbling as AI tools render it faster and more affordable to launch attacks on systems. "Identifying vulnerabilities and exploiting them has become incredibly straightforward," Guillemet stated in an interview.
"The cost is essentially dropping to zero." His comments come amidst a surge in high-profile crypto heists, including the recent $285 million exploit of Solana-based DeFi protocol Drift and the $25 million attack on yield protocol Resolv. According to DefiLlama, over $1.4 billion in assets were stolen or lost due to crypto attacks in the past year.
The traditional security paradigm, which relies on the notion that hacking a system should be more difficult and costly than the potential reward, is being upended by AI. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts. For cryptocurrency, where code often governs large pools of funds, this shift significantly raises the stakes. "You need to be flawless," Guillemet cautioned teams developing blockchain protocols.
The issue is further complicated by AI-generated code, which could lead to the rapid dissemination of vulnerabilities as more developers rely on AI tools. "There is no 'make it secure' button," he said. "We will produce a significant amount of code that is inherently insecure by design." To address this challenge, crypto protocols must rethink security from the ground up.
Guillemet advocates for formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits. He also emphasizes the importance of hardware-based security, such as devices that isolate private keys from internet-connected systems, thereby reducing exposure. "When you have a dedicated device that is not exposed to the internet, it is more secure by design," he explained. As malware becomes increasingly sophisticated, this approach is becoming more relevant.
Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction. For average cryptocurrency users, Guillemet's message is clear: assume that systems can and will fail. "You cannot trust most of the systems you use," he said. This may lead to a greater adoption of cold storage, stronger operational security, and keeping sensitive data offline.
However, even these measures are not foolproof, as risks extend beyond software to include physical attacks targeting cryptocurrency holders. Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep pace. "It's becoming increasingly easier to hack everything," he warned.