The crypto industry has long been plagued by hacking incidents and exploits, and now artificial intelligence is exacerbating this issue. Charles Guillemet, chief technology officer at Ledger, a prominent crypto wallet provider, believes that the economic foundations of cybersecurity are crumbling as AI tools make it faster and more affordable to launch attacks on systems. According to Guillemet, identifying and exploiting vulnerabilities has become significantly easier due to AI.
"The cost of doing so is essentially zero," he stated in an interview with CoinDesk. His comments come amidst a series of high-profile crypto heists. Recently, the Solana-based decentralized finance protocol Drift was exploited, resulting in the theft of $285 million worth of digital assets.
This incident is one of the most severe exploits of the year so far. Just a week prior, an attack on the yield protocol Resolv led to $25 million in losses. Data from DefiLlama indicates that over $1.4 billion in assets were stolen or lost due to crypto attacks over the past year.
The traditional security model relies on an imbalance, where it is more difficult and expensive to hack a system than the potential reward. However, AI is eroding this advantage. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds using the right prompts.
For the crypto industry, where code often controls large pools of funds, this shift significantly raises the stakes. Guillemet warned development teams that they must be perfect in their efforts.
The problem is further complicated by AI-generated code, which can spread vulnerabilities more quickly as more developers rely on AI tools. Guillemet emphasized that there is no straightforward solution to making code secure, stating, "We will produce a lot of code that is insecure by design." To address this issue, crypto protocols must rethink their security approach from the ground up. Guillemet suggested that formal verification, which involves using mathematical proofs to validate code, is a more robust method than traditional audits, which may overlook bugs.
He also emphasized the importance of hardware-based security, such as devices that isolate private keys from internet-connected systems, thereby reducing exposure. "When you have a dedicated device that is not exposed to the internet, it is more secure by design," Guillemet explained.
This approach is becoming increasingly relevant as malware becomes more sophisticated. Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction. For average crypto users, Guillemet's message is clear: assume that systems can and will fail. "You cannot trust most of the systems you use," he stated.
This may lead more users to adopt cold storage, strengthen their operational security, and keep sensitive data offline. However, even these measures are not foolproof, as risks extend beyond software to include physical attacks targeting crypto holders.
Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep up. "It's becoming easier to hack everything," he warned.