The crypto industry has long been plagued by hacking incidents and exploits, and now artificial intelligence is exacerbating the problem. According to Charles Guillemet, chief technology officer at Ledger, a leading crypto wallet provider, the economics of cybersecurity are deteriorating as AI tools make it faster and cheaper to launch attacks on systems. "Identifying and exploiting vulnerabilities has become extremely easy," Guillemet explained in an interview, adding that "the cost is essentially zero." His comments come at a time when crypto heists are once again making headlines, with the recent exploitation of Solana-based DeFi protocol Drift resulting in the theft of $285 million worth of digital assets.
This incident is one of the most severe crypto exploits this year, following a $25 million attack on yield protocol Resolv just a week prior. Over the past year, crypto attacks have resulted in the loss of over $1.4 billion in assets, according to data from DefiLlama. The traditional security approach, which relies on the imbalance between the cost of launching an attack and the potential reward, is being eroded by AI. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts.
For the crypto industry, where code often controls large pools of funds, this shift significantly raises the stakes. "You need to be perfect," Guillemet cautioned teams developing blockchain protocols. The problem is further complicated by AI-generated code, which could lead to the rapid spread of vulnerabilities as more developers rely on AI tools.
Guillemet emphasized that there is no straightforward solution to making code secure, stating, "We are going to produce a lot of code that will be insecure by design." To address this issue, crypto protocols must rethink their security approach from the ground up. Guillemet recommended formal verification, which involves using mathematical proofs to validate code, as a more robust method than traditional audits, which may overlook bugs. He also highlighted hardware-based security as an additional layer of protection, citing devices like hardware wallets that isolate private keys from internet-connected systems, thereby reducing exposure. "When you have a dedicated device not exposed to the internet, it is more secure by design," he noted.
This approach is becoming increasingly relevant as malware grows more sophisticated. Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction. For average crypto users, Guillemet's message is clear: assume that systems can and will fail.
"You can't trust most of the systems you use," he warned. This may lead to a greater adoption of cold storage, stronger operational security, and keeping sensitive data offline.
However, even these measures carry risks, including physical attacks targeting crypto holders. Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep up.
"It's really easier to hack everything," he concluded.