Ledger CTO Guillemet: AI Has Disrupted the Balance of Attack and Defense
Ledger's Chief Technology Officer Charles Guillemet has publicly warned that the widespread adoption of artificial intelligence technology has leveled the long-standing advantage that defenders have had over attackers in the field of crypto security.
Guillemet believes that in the past, defenders (security teams, auditing firms, wallet manufacturers) often held a relative advantage in their confrontations with attackers due to more specialized technical resources and systematic risk identification capabilities. However, with the proliferation of AI tools, attackers can also leverage AI to significantly enhance the efficiency of vulnerability discovery, phishing script generation, and malicious code writing, quickly bridging the existing technical gap.
At the same time, Guillemet criticized a behavior pattern he termed "engagement-farming bug disclosures," where some security researchers or self-media accounts disclose vulnerability information in a sensational manner to gain attention and traffic on social media, rather than through responsible channels.
He characterized this behavior as "attention farming with someone else's risk," indicating that while such disclosures bring attention and reputational benefits to the disclosers, the actual risk of vulnerabilities being maliciously exploited falls on ordinary users, protocol parties, and related ecosystem participants, creating a mismatch between the beneficiaries and the risk bearers.
As one of the world's leading manufacturers of crypto hardware wallets, Ledger has long been a focal point for vulnerability reports and security research in the crypto asset security field. Guillemet's statements reflect concerns within the industry regarding the current disorder in the vulnerability disclosure ecosystem, where traffic-driven disclosure methods may conflict with traditional responsible disclosure mechanisms.
From an industry impact perspective, if AI has indeed systematically leveled the technical barriers between attackers and defenders, it means that wallet manufacturers, exchanges, and protocol parties that rely on traditional manual audits and response speeds to build security moats will need to reassess their security investment structures. Those who are the first to apply AI capabilities to proactive defenses (such as AI-assisted anomaly transaction monitoring and automated smart contract auditing) may re-establish relative advantages in the new round of attack and defense games, with industry security spending expected to further tilt towards AI-driven defense tools.
Source: Public Information
ABAB AI Insight
Since its establishment in 2014, Ledger has built a benchmark position in the field of crypto asset storage security with its hardware cold wallet products. However, the company previously faced a massive data breach in 2020, exposing personal information of hundreds of thousands of users. Since then, Ledger has continued to increase its investment in security response and user education. As the company's CTO, Guillemet has also publicly addressed threats such as phishing attacks and supply chain attacks multiple times.
The capital investment paths for AI technology on both the attack and defense sides are showing divergence—attackers can utilize open-source large models or commercial AI tools to generate phishing emails, deepfake audio and video, and automated vulnerability scanning scripts at almost zero cost, resulting in very low marginal costs. In contrast, defenders need to continuously invest in training data, model fine-tuning, and specialized security teams to build AI security tools with equivalent capabilities, leading to a significantly higher capital investment threshold. This asymmetric investment is the underlying reason for Guillemet's assertion that "the defensive advantage has been leveled."
This phenomenon is highly similar to the historical trajectory of the traditional cybersecurity industry, which transitioned from "virus-killing software holding the advantage" to "black market groups using automated tools to rapidly iterate attack methods and close the gap." The crypto industry is currently replicating this turning point—previously, the crypto security industry widely believed that professional auditing firms and hardware wallet manufacturers held the technical high ground, but now, with the proliferation of AI tools, this high ground is being systematically weakened.
Essentially, this is a restructuring of the attack and defense dynamics driven by technological substitution—AI, as a general productivity tool, enhances the efficiency of both attackers and defenders. However, since attackers are typically not constrained by compliance and auditing processes, they can more quickly translate AI capabilities into practical attack capabilities, while defenders are limited by product release cycles and compliance reviews, leading to a structural misalignment in the speed of AI benefits being realized on both sides. This is the core mechanism behind the judgment that "the defender's advantage has been leveled."
ABAB News · Cognitive Laws
- AI does not distinguish between good and evil; whoever uses it first wins.
- Traffic arbitrage in vulnerability disclosures is exchanging others' risks for one's own attention.
- Once the technical barriers are leveled, the competition is about response speed.