The cryptocurrency sector has long been plagued by hacking incidents and exploits, and now artificial intelligence is exacerbating this issue. According to Charles Guillemet, the chief technology officer at Ledger, a provider of cryptocurrency wallets, the economic underpinnings of cybersecurity are disintegrating as AI tools render it faster and more cost-effective to compromise systems.
Guillemet stated in an interview with CoinDesk, "Identifying vulnerabilities and exploiting them has become remarkably easy. The expense is essentially zero." His comments come at a time when cryptocurrency heists are once again making headlines.
Just this week, the Solana-based decentralized finance protocol Drift was compromised, resulting in the theft of $285 million in digital assets. This incident is one of the most severe exploits of the year to date.
A week prior, an attack on the yield protocol Resolv resulted in losses of $25 million. Over the course of the past year, more than $1.4 billion in assets have been stolen or lost due to cryptocurrency attacks, according to data compiled by DefiLlama.
The traditional security paradigm has relied on an imbalance, where the effort and expense required to compromise a system should exceed the potential reward. However, AI is eroding this advantage. Tasks that once required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in mere seconds with the appropriate prompts.
For the cryptocurrency sector, where code often governs substantial pools of funds, this shift significantly elevates the stakes. Guillemet cautioned development teams for blockchain protocols, "You must be flawless." The issue is further complicated by AI-generated code. As more developers rely on AI tools, vulnerabilities may spread more rapidly. Guillemet noted, "There is no 'make it secure' button.
We will produce a substantial amount of code that will be insecure by design." To address this challenge, cryptocurrency protocols must rethink security from its foundation. Guillemet advocated for formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits, which may overlook bugs. He also emphasized the importance of hardware-based security.
Devices such as hardware wallets isolate private keys from internet-connected systems, thereby reducing exposure. "When you have a dedicated device that is not exposed to the internet, it is more secure by design," he explained. This approach is becoming increasingly relevant as malware becomes more sophisticated.
Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction. For average cryptocurrency users, Guillemet's message is straightforward: assume that systems can and will fail. "You cannot trust most of the systems you use," Guillemet said. This may lead more users to adopt cold storage, strengthen operational security, and keep sensitive data offline.
Even so, risks extend beyond software, including physical attacks targeting cryptocurrency holders. Guillemet anticipates a divide in the future.
Critical systems, such as wallets and protocols, will invest heavily in security and adapt. However, much of the broader software ecosystem may struggle to keep pace.
"It's really easier to hack everything," he stated.