The crypto industry has long been plagued by hacking incidents and exploits, and now artificial intelligence is exacerbating the issue. Charles Guillemet, Ledger's chief technology officer, believes that the economic framework of cybersecurity is disintegrating as AI tools facilitate faster and more affordable system attacks. Guillemet stated, "Identifying and exploiting vulnerabilities has become extremely simple.
The cost is essentially zero." His comments come amidst a string of high-profile crypto heists, including the recent $285 million exploit of Solana-based Drift and the $25 million attack on yield protocol Resolv. According to DefiLlama, over $1.4 billion in assets were stolen or lost due to crypto attacks in the past year. The traditional security approach, which relies on the imbalance between the cost of hacking and the potential reward, is being eroded by AI.
Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts. For crypto, where code often controls large pools of funds, this shift raises the stakes.
Guillemet warned developers of blockchain protocols, "You need to be perfect." The problem is further complicated by AI-generated code, which can spread vulnerabilities more quickly. Guillemet emphasized, "There is no 'make it secure' button. We will produce a lot of code that is inherently insecure by design." To address this issue, crypto protocols must rethink security from the ground up. Guillemet suggested formal verification, which uses mathematical proofs to validate code, as a more robust approach than traditional audits.
He also recommended hardware-based security, such as devices that isolate private keys from internet-connected systems, reducing exposure. For average crypto users, Guillemet's message is clear: assume that systems can and will fail. "You can't trust most of the systems you use," he said. This may lead more users to adopt cold storage, stronger operational security, and keeping sensitive data offline.
However, even these measures carry risks, including physical attacks targeting crypto holders. Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep up. "It's really easier to hack everything," he warned.