The crypto industry has long been plagued by hacking incidents and exploits. However, the situation is becoming even more dire due to the impact of artificial intelligence, which is making it faster and cheaper for hackers to launch attacks. This is the warning from Charles Guillemet, the Chief Technology Officer at Ledger, a leading provider of crypto wallets. According to Guillemet, the economics of cybersecurity are breaking down as AI tools make it easier for attackers to identify and exploit vulnerabilities.
In a recent interview, Guillemet stated that "finding vulnerabilities and exploiting them becomes really, really easy" and that "the cost is going down to zero." His comments come at a time when the crypto space is experiencing a surge in high-profile hacking incidents. For instance, the Solana-based decentralized finance protocol Drift was recently exploited, resulting in the theft of $285 million worth of digital assets. Similarly, an attack on the yield protocol Resolv led to losses of $25 million.
Over the past year, crypto attacks have resulted in the theft or loss of over $1.4 billion in assets, according to data from DefiLlama. The traditional approach to security has relied on the idea that it should be more difficult and expensive to hack a system than the potential reward. However, AI is eroding this advantage by enabling tasks that once required months of work by skilled researchers to be completed in seconds. For the crypto industry, where code often controls large pools of funds, this shift raises the stakes.
Guillemet warned that developers of blockchain protocols need to be perfect in their approach to security. The problem is further compounded by the use of AI-generated code, which can spread vulnerabilities more quickly. As Guillemet noted, "there is no 'make it secure' button" and the industry is likely to produce a lot of code that is insecure by design. To address this issue, Guillemet suggests that crypto protocols need to rethink their approach to security from the ground up.
He recommends the use of formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits. Additionally, hardware-based security can provide an extra layer of protection by isolating private keys from internet-connected systems. For average crypto users, Guillemet's message is clear: assume that systems can and will fail.
As he stated, "you can't trust most of the systems that you use." This could lead to a greater adoption of cold storage, stronger operational security, and keeping sensitive data offline. However, even these measures are not foolproof, and risks extend beyond software to include physical attacks targeting crypto holders. Guillemet expects that the industry will become increasingly divided, with critical systems like wallets and protocols investing heavily in security and adapting to the new landscape, while much of the broader software ecosystem may struggle to keep up. As he noted, "it's really easier to hack everything."