The crypto sector has long been plagued by cyberattacks and security breaches, but the situation is now worsening due to the impact of artificial intelligence. Charles Guillemet, the chief technology officer at Ledger, a prominent crypto wallet provider, has stated that the economic viability of cybersecurity is deteriorating as AI-powered tools facilitate faster and more affordable system attacks.
Guillemet emphasized that identifying and exploiting vulnerabilities has become exceedingly simple, with the associated costs approaching zero. His comments come at a time when crypto heists are once again making headlines, with recent incidents including the exploitation of Solana-based DeFi protocol Drift, resulting in the loss of $285 million in digital assets, and the attack on yield protocol Resolv, which led to $25 million in losses.
Over the past year, crypto attacks have resulted in the theft or loss of over $1.4 billion in assets, according to data from DefiLlama. The traditional security paradigm, which relies on the notion that hacking a system should be more difficult and expensive than the potential reward, is being eroded by AI. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts.
For the crypto industry, where code often controls large pools of funds, this shift significantly raises the stakes. Guillemet warned development teams that they need to be flawless in their approach.
The problem is further complicated by AI-generated code, which can spread vulnerabilities more quickly as more developers rely on AI tools. Guillemet noted that there is no single solution to guarantee security, and the industry will likely produce a significant amount of insecure code by design.
To address this issue, crypto protocols must rethink their security from the ground up. Guillemet suggested that formal verification, which involves using mathematical proofs to validate code, is a more robust approach than traditional audits, which may miss bugs. He also highlighted the importance of hardware-based security, such as devices that isolate private keys from internet-connected systems, reducing exposure.
When a dedicated device is not exposed to the internet, it is inherently more secure, according to Guillemet. This approach is becoming increasingly relevant as malware becomes more sophisticated, with attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction.
For average crypto users, Guillemet's message is clear: assume that systems can and will fail. He stated that users cannot trust most of the systems they use, which may lead to a greater adoption of cold storage, stronger operational security, and keeping sensitive data offline. However, even these measures carry risks, including physical attacks targeting crypto holders. Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep up.
Ultimately, he warned that it is becoming increasingly easier to hack everything.