The crypto industry has long been plagued by hacker attacks and security breaches. However, the emergence of artificial intelligence (AI) has significantly intensified this threat.
According to Charles Guillemet, Chief Technology Officer at Ledger, a leading crypto wallet provider, the economic foundations of cybersecurity are disintegrating as AI tools render it faster and more cost-effective to compromise systems. Guillemet emphasized that identifying and exploiting vulnerabilities has become remarkably straightforward, with the associated costs approaching zero. His comments come at a time when crypto heists are once again making headlines, with the recent exploitation of Solana-based decentralized finance protocol Drift resulting in the theft of $285 million worth of digital assets, and an earlier attack on yield protocol Resolv leading to $25 million in losses. Over the past year, crypto attacks have resulted in the loss or theft of over $1.4 billion in assets, according to data from DefiLlama.
Historically, security has relied on an imbalance, where the difficulty and expense of hacking a system outweighed the potential reward. Nevertheless, AI is eroding this advantage, as tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts.
For the crypto sector, where code often controls substantial pools of funds, this shift significantly raises the stakes. Guillemet cautioned development teams working on blockchain protocols that they must strive for perfection. The issue is further complicated by AI-generated code, which could lead to the rapid dissemination of vulnerabilities as more developers rely on AI tools. Guillemet noted that there is no straightforward solution to guarantee security, and the industry is likely to produce a significant amount of code that is inherently insecure.
To address this challenge, crypto protocols must rethink their approach to security from the ground up. Guillemet advocated for formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits, which may overlook bugs. He also highlighted the importance of hardware-based security, such as devices that isolate private keys from internet-connected systems, thereby reducing exposure. For average crypto users, Guillemet's message is clear: assume that systems can and will fail.
As a result, users may be forced to adopt more stringent security measures, such as cold storage, robust operational security, and keeping sensitive data offline. However, even these measures are not foolproof, as risks extend beyond software to include physical attacks targeting crypto holders. Guillemet anticipates a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep pace. Ultimately, the increasing ease of hacking poses a significant challenge to the crypto industry, and it is essential for stakeholders to reassess their approach to security in light of the emerging AI landscape.