The cryptocurrency landscape has long been plagued by hacking incidents and exploits, but the situation is now being exacerbated by artificial intelligence, according to Charles Guillemet, Chief Technology Officer at Ledger, a prominent crypto wallet provider. Guillemet argues that the economic foundations of cybersecurity are crumbling as AI tools make it faster and more cost-effective to launch attacks on systems.
In a recent interview with CoinDesk, Guillemet stated, "Identifying and exploiting vulnerabilities has become remarkably easy. The cost is essentially zero." His comments come at a time when crypto heists are once again making headlines. Just recently, the Solana-based decentralized finance protocol Drift was exploited, resulting in the theft of $285 million worth of digital assets.
This incident is one of the most severe exploits of the year so far. The week prior, an attack on the yield protocol Resolv led to $25 million in losses. According to data from DefiLlama, over $1.4 billion in assets were stolen or lost in crypto attacks over the past year. The traditional security paradigm has relied on an imbalance, where it is more difficult and expensive to hack a system than the potential reward.
However, AI is eroding this advantage. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts. For the crypto industry, where code often controls large pools of funds, this shift significantly raises the stakes.
Guillemet warned development teams, "You need to be perfect." The problem is further complicated by AI-generated code, which could lead to the rapid spread of vulnerabilities as more developers rely on AI tools. Guillemet emphasized, "There is no 'make it secure' button. We will produce a lot of code that will be insecure by design." To address this issue, crypto protocols must rethink security from the ground up.
Guillemet suggested formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits, which may overlook bugs. He also highlighted hardware-based security as an additional layer, citing devices like hardware wallets that isolate private keys from internet-connected systems, thereby reducing exposure. When you have a dedicated device that is not exposed to the internet, it is more secure by design, he explained.
This approach is becoming increasingly relevant as malware becomes more sophisticated. Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction. For average crypto users, Guillemet's message is clear: assume that systems can and will fail. You can’t trust most of the systems that you use, he said.
This could lead more users to adopt cold storage, strengthen operational security, and keep sensitive data offline. However, even then, risks extend beyond software, including physical attacks targeting crypto holders.
Guillemet predicts a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, but much of the broader software ecosystem may struggle to keep up. It’s really easier to hack everything, he said.