The cryptocurrency sector has long been plagued by hacking incidents and exploits, and now artificial intelligence is making this threat even more severe. Charles Guillemet, Chief Technology Officer at Ledger, a prominent crypto wallet provider, states that the economic principles of cybersecurity are collapsing as AI tools render it faster and more affordable to launch attacks on systems. Guillemet emphasized that identifying and exploiting vulnerabilities has become increasingly straightforward, with the associated costs dwindling to nearly zero. His comments come amidst a recent surge in high-profile crypto heists, including the $285 million exploit of Solana-based DeFi protocol Drift and the $25 million attack on yield protocol Resolv.
Over the past year, crypto attacks have resulted in the loss or theft of over $1.4 billion in assets, according to data from DefiLlama. The traditional security paradigm, which relies on the notion that hacking a system should be more difficult and expensive than the potential reward, is being eroded by AI. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in a matter of seconds with the right prompts. For the crypto industry, where code often controls substantial funds, this shift significantly raises the stakes.
Guillemet cautioned development teams that they must strive for perfection, as even minor vulnerabilities can have severe consequences. The issue is further complicated by AI-generated code, which can spread vulnerabilities more quickly as more developers rely on AI tools. Guillemet emphasized that there is no straightforward solution to ensure security, stating that the industry will likely produce a significant amount of insecure code by design. To address this challenge, Guillemet recommends that crypto protocols rethink their security approach from the ground up.
He suggests that formal verification, which involves using mathematical proofs to validate code, is a more robust approach than traditional audits. Additionally, hardware-based security can provide an extra layer of protection, as devices like hardware wallets isolate private keys from internet-connected systems, reducing exposure. Guillemet's message to average crypto users is clear: assume that systems can and will fail, and take necessary precautions to protect themselves.
This may involve using cold storage, implementing stronger operational security measures, and keeping sensitive data offline. However, even these precautions are not foolproof, as risks extend beyond software to include physical attacks targeting crypto holders. Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep up.