The cryptocurrency landscape has long been plagued by hacking incidents and exploits, a problem that has been further complicated by the rise of artificial intelligence. According to Charles Guillemet, the Chief Technology Officer at Ledger, a leading crypto wallet provider, the increasing accessibility of AI tools has made it significantly easier and cheaper for attackers to compromise systems.
Guillemet emphasized that the traditional economic model of cybersecurity, which relies on the principle that the cost of attacking a system should outweigh the potential gains, is no longer effective. "Identifying and exploiting vulnerabilities has become exceedingly simple," he noted in an interview.
"The cost is essentially negligible." His comments come at a time when crypto heists are once again making headlines. Recently, the Solana-based DeFi protocol Drift was exploited, resulting in the loss of $285 million in digital assets. This incident is one of the most significant exploits of the year to date. Just a week prior, an attack on the yield protocol Resolv resulted in $25 million in losses.
According to data from DefiLlama, the total value of assets stolen or lost in crypto attacks over the past year exceeds $1.4 billion. The traditional security paradigm has been based on an imbalance, where the difficulty and expense of hacking a system should deter potential attackers. However, the advent of AI has disrupted this equilibrium. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in a matter of seconds with the right prompts.
For the crypto industry, where code often controls substantial funds, this shift significantly raises the stakes. Guillemet cautioned teams developing blockchain protocols that they must strive for perfection. The issue is further complicated by the proliferation of AI-generated code.
As more developers rely on AI tools, the potential for vulnerabilities to spread rapidly increases. Guillemet stressed that there is no straightforward solution to ensure security. "We are likely to produce a significant amount of code that is inherently insecure by design," he warned.
To address this challenge, crypto protocols must rethink their approach to security from the ground up. Guillemet advocates for formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits. He also emphasizes the importance of hardware-based security, such as devices that isolate private keys from internet-connected systems, thereby reducing exposure.
For average crypto users, Guillemet's message is clear: it is essential to assume that systems can and will fail. "You cannot trust most of the systems you use," he said. This realization may lead more users to adopt cold storage, prioritize operational security, and keep sensitive data offline.
However, even these measures are not foolproof, as risks extend beyond software to include physical attacks targeting crypto holders. Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep pace. "It has become significantly easier to hack virtually everything," he concluded.