The cryptocurrency sector has long been plagued by hacking incidents and exploits, and the situation is being exacerbated by artificial intelligence. Charles Guillemet, the chief technology officer at Ledger, a prominent crypto wallet provider, believes that AI is disrupting the economics of cybersecurity by making it quicker and less expensive to launch attacks on systems. "Identifying and exploiting vulnerabilities has become remarkably easy," Guillemet stated in an interview.
"The cost is essentially dropping to zero." His comments come at a time when high-profile crypto heists are making headlines. Recently, the Solana-based decentralized finance protocol Drift was exploited, resulting in the theft of $285 million worth of digital assets, marking one of the most severe exploits this year. The week prior, an attack on the yield protocol Resolv led to $25 million in losses. According to data from DefiLlama, over $1.4 billion in assets were stolen or lost due to crypto attacks over the past year.
The traditional security approach has relied on an imbalance, where the cost of hacking a system should outweigh the potential reward. However, AI is eroding this advantage by enabling tasks that once required skilled researchers months to complete, such as reverse engineering software or chaining exploits, to be accomplished in mere seconds with the right prompts. For the crypto sector, where code often controls substantial funds, this shift significantly raises the stakes. Guillemet cautioned teams developing blockchain protocols, stating, "You need to be perfect." The issue is further complicated by AI-generated code, which could lead to the rapid spread of vulnerabilities as more developers rely on AI tools.
Guillemet emphasized, "There is no 'make it secure' button. We will produce a lot of code that is insecure by design." To address this, crypto protocols must rethink security from the ground up. Guillemet suggested that formal verification, which involves using mathematical proofs to validate code, is a more robust approach than traditional audits, which may miss bugs. He also highlighted the importance of hardware-based security, such as devices like hardware wallets that isolate private keys from internet-connected systems, thereby reducing exposure.
"When you have a dedicated device not exposed to the internet, it is more secure by design," he explained. As malware becomes increasingly sophisticated, this approach is gaining relevance.
Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction. For average crypto users, Guillemet's message is straightforward: assume that systems can and will fail. "You can’t trust most of the systems that you use," he said.
This may lead more users to adopt cold storage, enhance operational security, and keep sensitive data offline. However, even then, risks persist, including physical attacks targeting crypto holders.
Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep up. "It’s really easier to hack everything," he warned.