The cryptocurrency sector has long been plagued by hacking incidents and security breaches. However, the advent of artificial intelligence (AI) has significantly exacerbated this issue.
Charles Guillemet, the Chief Technology Officer at Ledger, a prominent crypto wallet provider, asserts that the economic landscape of cybersecurity is deteriorating as AI tools render it increasingly faster and cheaper to launch attacks on systems. "Identifying vulnerabilities and exploiting them has become remarkably straightforward," Guillemet stated in an interview with CoinDesk. "The associated costs are essentially plummeting to zero." His comments come at a time when crypto heists are once again making headlines. Recently, the Solana-based decentralized finance protocol Drift suffered an exploit, resulting in the loss of $285 million worth of digital assets.
This incident is one of the most severe exploits of the year thus far. Just a week prior, an attack on the yield protocol Resolv led to losses amounting to $25 million. According to data compiled by DefiLlama, the total value of assets stolen or lost in crypto attacks over the past year exceeds $1.4 billion.
The traditional security paradigm, which relies on the premise that hacking a system should be more challenging and expensive than the potential reward, is being eroded by AI. Tasks that previously required skilled researchers months to accomplish, such as reverse engineering software or chaining exploits, can now be completed in mere seconds with the right prompts. For the cryptocurrency sector, where code often governs large pools of funds, this shift significantly raises the stakes. "You need to be flawless," Guillemet cautioned teams developing blockchain protocols.
The problem is further complicated by AI-generated code, which could lead to the rapid dissemination of vulnerabilities as more developers rely on AI tools. "There is no magical 'make it secure' button," he noted.
"We are likely to produce a substantial amount of code that will be inherently insecure by design." To address this issue, crypto protocols must rethink their security frameworks from the ground up. Guillemet emphasized the importance of formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits that may overlook bugs. He also highlighted the significance of hardware-based security, such as devices that isolate private keys from internet-connected systems, thereby reducing exposure. "When you have a dedicated device that is not exposed to the internet, it is more secure by design," he explained.
This approach is becoming increasingly relevant as malware grows more sophisticated. Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction. For average cryptocurrency users, Guillemet's message is straightforward: assume that systems can and will fail. "You cannot trust most of the systems you use," Guillemet stated.
This could lead more users to adopt cold storage, strengthen their operational security, and keep sensitive data offline. Even then, risks extend beyond software, including physical attacks targeting cryptocurrency holders. Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep pace. "It has become significantly easier to hack everything," he concluded.