The crypto industry has long been plagued by hacking attacks and exploits, but the situation is worsening due to the advent of artificial intelligence. According to Charles Guillemet, Chief Technology Officer at Ledger, a leading crypto wallet provider, AI is making it faster and cheaper for hackers to attack systems, thus rendering the economics of cybersecurity obsolete. Guillemet stated that "identifying and exploiting vulnerabilities has become extremely easy" and that "the cost is approaching zero." His comments come at a time when crypto heists are making headlines, with the recent Solana-based Drift protocol exploit resulting in the theft of $285 million in digital assets and the yield protocol Resolv attack leading to $25 million in losses. Over the past year, crypto attacks have resulted in the theft or loss of over $1.4 billion in assets, according to data from DefiLlama.
Traditionally, security has relied on the principle of asymmetry, where it is more difficult and costly to hack a system than the potential reward. However, AI is eroding this advantage, as tasks that once required skilled researchers months to complete can now be accomplished in seconds using the right prompts. For the crypto industry, where code often controls large pools of funds, this shift raises the stakes.
Guillemet warned that developers of blockchain protocols must be perfect, as the slightest vulnerability can have significant consequences. The problem is further complicated by AI-generated code, which can spread vulnerabilities more quickly. Guillemet emphasized that there is no simple solution to making code secure and that the industry will produce a lot of insecure code by design. To address this issue, Guillemet suggested that crypto protocols must rethink their security approach from the ground up.
He recommended using formal verification, which involves mathematical proofs to validate code, as a more robust method than traditional audits. Additionally, Guillemet highlighted the importance of hardware-based security, such as devices that isolate private keys from internet-connected systems, reducing exposure to potential threats.
For average crypto users, Guillemet's message is clear: assume that systems can and will fail. As a result, users may need to adopt more secure practices, such as using cold storage, implementing stronger operational security, and keeping sensitive data offline. Guillemet expects that critical systems, such as wallets and protocols, will invest heavily in security and adapt to the new landscape, while much of the broader software ecosystem may struggle to keep up. Ultimately, the increasing ease of hacking poses a significant challenge to the crypto industry, and Guillemet's warning serves as a reminder of the need for vigilance and robust security measures to protect against potential threats.