The cryptocurrency sector has long been plagued by cyber attacks and security breaches. However, according to Charles Guillemet, Chief Technology Officer at Ledger, a leading crypto wallet provider, the rise of artificial intelligence (AI) is amplifying this threat. Guillemet argues that AI-powered tools are making it faster and more cost-effective for hackers to identify and exploit vulnerabilities, thereby disrupting the economics of cybersecurity. "Identifying and exploiting vulnerabilities has become extremely easy," Guillemet noted in an interview.
"The cost of doing so is essentially zero." This warning comes as the crypto industry is once again dealing with high-profile security breaches. Recently, the Solana-based decentralized finance protocol Drift was hacked, resulting in the theft of $285 million worth of digital assets. This incident is one of the most severe exploits of the year so far. Just a week prior, an attack on the yield protocol Resolv led to $25 million in losses.
According to data from DefiLlama, over $1.4 billion in assets were stolen or lost due to crypto attacks over the past year. The traditional security approach has relied on an imbalance, where it is more difficult and expensive to hack a system than the potential reward. Nevertheless, AI is eroding this advantage, as tasks that once required months of work by skilled researchers can now be accomplished in seconds using the right prompts. For the crypto industry, where code often controls large amounts of funds, this shift significantly raises the stakes.
"You need to be perfect," Guillemet cautioned teams developing blockchain protocols. The problem is further complicated by AI-generated code, which can spread vulnerabilities more quickly as more developers rely on AI tools. "There is no magic button to make something secure," he said. "We will produce a lot of code that is inherently insecure by design." To address this issue, crypto protocols must rethink security from the ground up.
Guillemet suggested that formal verification, which uses mathematical proofs to validate code, is a more robust approach than traditional audits, which may miss bugs. He also emphasized the importance of hardware-based security, such as devices like hardware wallets that isolate private keys from internet-connected systems, reducing exposure. "When you have a dedicated device that is not exposed to the internet, it is more secure by design," he explained. This approach is becoming increasingly relevant as malware grows more sophisticated.
Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction. For average crypto users, Guillemet's message is clear: assume that systems can and will fail. "You cannot trust most of the systems you use," he said. This may lead more users to adopt cold storage, stronger operational security, and keeping sensitive data offline.
However, even then, risks extend beyond software, including physical attacks targeting crypto holders. Guillemet expects a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep up.
"It's becoming increasingly easy to hack everything," he warned.