Ledger CTO Charles Guillemet: AI Makes Attacks Cheaper, Architecture Must Change
Ledger CTO Charles Guillemet commented on the Bitget hot wallet being drained, resulting in over $350 million stolen, calling it possibly the largest hacking case of the year. Crypto security has always been challenging, and AI has lowered the cost of vulnerability research and exploitation, further asymmetrically favoring attackers. To fill the gap, a complete overhaul of security paradigms and architecture is necessary, rather than just applying patches.
He has repeatedly explained the same curve this year: finding vulnerabilities, writing exploits, and testing against forked chains, which previously required skilled researchers weeks, can now be done in hours with prompt words. Anthropic's red team and subsequent papers have indicated that approximately $1.22 in API credits can generate usable contract exploits; the asymmetry in attack and defense costs is evident, with attackers able to extract value for about $6,000 to profit, while defenders need closer to $60,000 to break even, as defense must cover all bases while offense only needs to succeed once.
Bitget's official loss is locked at $351.6 million, with 19 transfers coming from hot and warm wallets, excluding private keys, with the path being used in the backend to call the signing machine. Guillemet did not comment on specific intrusion tools but placed the incident within the structure of "hot wallets must be online, and AI allows for scalable scanning." Ledger's core business is offline private keys and hardware isolation, with the commercial conclusion being to reduce the attack surface, create controllable models for defense, and use cryptography to make entire classes of attacks impossible, rather than relying on the next configuration hardening.
In September, he collaborated with Trezor and others to promote coordinated disclosure: AI has made finding vulnerabilities cheaper, and responsible disclosure cannot become optional, with a baseline silence period of 90 days. Defenders also face usage policies from model suppliers: attackers are unrestricted, while defenders may be blocked from the best models by security barriers.
In market mechanisms, what is sold is the convenience of online hot wallets, while what is bought is the signing rights that can be called by work orders. AI has driven the marginal cost of attacks close to computational bills, and exchange insurance funds cover the costs without changing the next scanning costs. Beneficiaries are hardware wallets, formal verification, and self-custody tool providers, while centralized platforms that must maintain hot wallet liquidity are under pressure. Funds flow from user balances through hot wallets to attack addresses, and security budgets shift from post-incident compensation to architectural redesign.
Source: Public Information
ABAB AI Insight
Guillemet has transitioned from a hardware security researcher to Ledger's technology head, maintaining a consistent stance: keys should not leave connected hosts. In April 2026, he told CoinDesk that exploitation costs had "dropped to near zero"; in July, he wrote about the asymmetry in offense and defense after Hugging Face was compromised; in September, he pushed for industry disclosure standards. The Bitget case provides the latest denominator—$351.6 million proves that hot wallets remain the largest single-point prize pool.
The capital path is Ledger selling devices and recovery services, while exchanges sell depth and withdrawal speed. AI has made it cheaper for both sides to write code, and it has also enabled both sides to quickly produce code with vulnerabilities. Those who keep signing rights in offline components block AI scanning at physical boundaries; those who connect signing machines to business backends leave interfaces for prompt words.
Similar migrations can be seen in aviation moving from "more careful pilots" to redundant fly-by-wire controls, and in payments transitioning from magnetic stripes to chip cards. Crypto still lingers in a patch culture: adding a layer of monitoring after each major theft without changing the necessity for hot wallets to remain hot.
Structural judgment belongs to technological substitution. Once human audits are replaced by model scanning, if defense still relies on human patches, the cost curve will inevitably lose. The mechanism is: offense only needs to succeed once, while defense must be correct forever; AI amplifies this inequality, forcing security to shift from "finding vulnerabilities" to "making entire classes of calls cryptographically invalid."
ABAB News · Law of Cognition
- Offense succeeds once, defense must be eternal.
- AI does not break cryptography; it breaks the labor hours needed to find vulnerabilities.
- Hot wallets exist to facilitate withdrawals, but also to be scanned.