The crypto industry has long been plagued by hacking incidents and exploits, but the situation is now worsening due to the impact of artificial intelligence. According to Charles Guillemet, Chief Technology Officer at Ledger, a leading crypto wallet provider, the economics of cybersecurity are deteriorating as AI tools make it faster and more affordable to launch attacks on systems. Guillemet explained that identifying vulnerabilities and exploiting them has become extremely easy, with the cost of doing so effectively dropping to zero.
His comments come at a time when crypto heists are once again making headlines, with recent incidents including the exploitation of Solana-based DeFi protocol Drift, resulting in the loss of $285 million in digital assets, and an attack on yield protocol Resolv, which led to $25 million in losses. Over the past year, more than $1.4 billion in assets have been stolen or lost due to crypto attacks, according to data from DefiLlama. The traditional security approach relies on an imbalance, where it should be more difficult and expensive to hack a system than the potential reward.
However, AI is eroding this advantage, as tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts. For the crypto industry, where code often controls large pools of funds, this shift raises the stakes significantly. Guillemet warned development teams that they need to be perfect in their approach to security.
The problem is further compounded by AI-generated code, which could lead to the rapid spread of vulnerabilities as more developers rely on AI tools. Guillemet emphasized that there is no straightforward solution to making code secure, and instead, a more robust approach is needed. To address this, Guillemet suggests that crypto protocols should rethink security from the ground up, utilizing formal verification, which involves using mathematical proofs to validate code, as a more effective method than traditional audits. He also recommends hardware-based security, such as devices like hardware wallets, which isolate private keys from internet-connected systems, reducing exposure.
When using a dedicated device that is not exposed to the internet, the security is inherently stronger, according to Guillemet. This approach is becoming increasingly relevant as malware grows more sophisticated, with attacks that can scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction. For average crypto users, Guillemet's message is clear: assume that systems can and will fail. Users should not trust most of the systems they use, and instead, should adopt a more cautious approach, such as using cold storage, strengthening operational security, and keeping sensitive data offline.
Even then, risks extend beyond software, including physical attacks targeting crypto holders. Guillemet expects a divide to emerge in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, but much of the broader software ecosystem may struggle to keep up. Ultimately, the increasing ease of hacking poses a significant challenge to the crypto industry, and it is essential to prioritize security to mitigate these risks.