EP - 119

AI Made Security Flaws Cheap to Find. What Now?

with

Mo El-Sayed & Charles Guillemet
Head of Brand Development & CTO @ Ledger

Sep 14, 2026

On this episode of The Ledger Podcast, Ledger CTO Charles Guillemet joins Head of Brand Development Mo El-Sayed to unpack why 2026 is on pace to be the worst year yet for crypto hacks, and what AI has to do with it. 

Drawing on two of the year’s biggest incidents, the Coldcard seed-generation flaw and the Liquid Bitcoin bridge exploit, Charles explains how large language models have collapsed the cost of finding and exploiting software vulnerabilities, upending the economics that used to keep systems “secure enough.” 

The conversation also covers Anthropic’s Glasswing guardrails and their limits, the open-source-versus-closed-source security debate, the ethics of “white hat” disclosure, and how Ledger’s own Donjon security team is fighting AI with AI through its Cerberus research harness. 

“The only thing you needed to do was just prompt Claude and ask it to find a vulnerability on this specific website — and that’s it.” – Charles Guillemet

Watch the full episode below:

Key Highlights:

How AI Collapsed the Attacker-Defender Asymmetry

Security has never meant “unbreakable”. Rather, it has meant making an attack cost more than it’s worth. If an asset is worth $1 million and breaking it costs an attacker $10 million, Charles explains, “your system is secure. Not 100% secure, but in practice, no one will spend $10 million to get $1 million.” 

That asymmetry used to be easy to maintain, because finding and exploiting a real vulnerability required “several very talented security researchers” spending a month or more. Starting around October and November of last year, that math flipped. Frontier AI models became efficient enough at both finding and exploiting bugs that the cost of an attack started trending toward zero. 

The result isn’t a level playing field: it’s worse than that. As Charles puts it, “we’re able to raise the bar for security, but at the same time, the bar to be secure has never been this high”, as a single mistake is now enough for an AI-assisted attacker to find and exploit it.

Guardrails, Glasswing, and the Limits of AI “Safety Theater”

Mo asks a popular question: don’t frontier labs put guardrails on these models specifically to prevent this? Charles is skeptical of how much that has mattered in practice. Anthropic’s Glasswing program gave a short list of US companies early, lighter-guardrail access to its Mythos-tier model, but he calls it “more PR than anything else,” since a highly capable model for finding and exploiting vulnerabilities already existed, and most of the world’s security teams were locked out of the program anyway. 

Guardrails also turned out to be simple to route around. After an AWS engineer publicized a systematic jailbreak, the U.S. government restricted Mythos access to American citizens and companies entirely, a rule Anthropic ultimately enforced by shutting the model down rather than trying to police individual users. 

Attackers who lose access to guarded frontier models simply switch to unrestricted open-source alternatives that carry no guardrails at all. He also points to the Hugging Face incident, where an AI system pursuing a goal found its own way around obstacles in its path.

“There’s no good and bad for an LLM… if it requires hacking a system… they’ll do it.” – Charles Guillemet 

Anatomy of the Coldcard Hack: When Low Entropy Meets AI

Above all else, a secure crypto wallet depends on a seed phrase generated with true, maximal randomness: 256 bits of entropy, with no deterministic shortcut for guessing it. A firmware bug introduced five years ago meant Coldcard devices were instead drawing from a dangerously small pool of possible seeds. 

Once attackers found the flaw (“most likely with AI,” Charles says), they could generate every possible seed, check which ones held funds onchain, and drain them. “As soon as you have all the seeds, you just look at the blockchain and steal the funds. That’s what happened.” 

Multiple waves of attackers piled in as the exploit became public knowledge on social media, and the total theft ran to roughly 1,200 BTC. To underline the speed problem, Charles describes how the Ledger Donjon reproduced the entire discovery process for testing purposes.

“We took the Coldcard codebase and asked Claude, ‘is there a vulnerability in here?’… within one minute, Claude was able to retrieve the vulnerability.” 

Open Source vs. Closed Source: Rethinking the Trust Model

The Coldcard incident reopened a long-running debate. While philosophically, “a strong advocate for open source” as a way of sharing knowledge, Charles makes clear that public code is not the same thing as secure code.

“Thinking that because your code is open source it will be secure, because people will look at it, is obviously wrong.” 

He references Kerckhoffs’s principle, stating that a well-built system should stay secure even if an attacker knows everything about it except the keys, so security should never depend on hiding how something works. In practice, though, withholding implementation details still raises the cost and time required to mount an attack, and open-source code hands attackers a head start they wouldn’t otherwise have. 

The logic extends to hardware, too: even a fully open-source Secure Element wouldn’t resolve the underlying trust problem, since there’s no way to verify that the physical silicon running in a device actually matches the published design. It’s why, in Charles’s view, a closed-source Secure Element isn’t a contradiction of Ledger’s security philosophy so much as a practical trade-off.

The Liquid Bridge Hack and the Ethics of “White Hat” Extortion

The episode’s other major case study is the attack on Liquid, Blockstream’s confidential Bitcoin layer-two network. A bug in how the bridge verified transactions let an attacker submit a request to bridge out roughly one Bitcoin, but actually withdraw 4,000 BTC. This flaw, Charles says, was “quite tricky, not easy to find at all,” and one AI played a role in surfacing.  

The attacker then contacted Blockstream directly onchain, using encrypted messages appended to OP_RETURN outputs, declared themselves “white hat,” and refused to return any funds until the underlying bug was fixed. Once it was, they sent back 3,400 BTC and kept 600 BTC, worth more than $40 million, as what they framed as a fair reward, something that Charles rejects outright: 

“This isn’t how security works. If you want to be white hat, you play by the rules.” 

Shrinking Patch Windows and the Rise of “Engagement Farming”

While firmware upgrades have always mattered, Charles says they’ve never mattered more, as AI collapses the time it takes to reverse-engineer what a patch actually fixes. “Give the binary to Claude, ask it what it does, and one minute later you have the answer,” including exactly which vulnerability was patched, and therefore exactly how to exploit anyone still running the old version. 

The practical effect is that “the time frame between a fix being released and attackers exploiting the vulnerability is minutes,” leaving little room for users who haven’t updated. Compounding the problem is a wave of self-styled “security researchers” who skip responsible disclosure entirely and publish critical findings on social media to farm attention, sometimes reporting bugs that were already found and quietly patched. Charles co-signed an open letter with other parts of the ecosystem asking researchers to report privately first.

Fighting Back: Ledger Donjon, Cerberus, and Security by Design

Ledger’s own answer to AI-accelerated attackers is Cerberus, an AI-orchestrated vulnerability-research harness built by the Ledger Donjon to audit code and patch flaws faster than adversaries can find them. The tool has already surfaced vulnerabilities in Ledger’s own systems “even knowing we have a Donjon team that’s been working on these systems for more than 10 years.” But Charles is clear that, as necessary as it is to race attackers, it is not sufficient in and of itself.

“If you only do this race, at some point an attacker will find something before you do, and you lose.” 

The more durable answer is security by design: mapping the threat model, minimizing the attack surface, and leaning on cryptography and formal verification wherever possible. This is precisely the philosophy behind hardware signers: Ledger turns an open-ended security problem into a narrow key-management one, isolating the one thing that actually matters (the private key) inside a Secure Element that’s physically disconnected from the internet, rather than trying to secure an entire general-purpose, connected device.

Key Predictions for the Next Decade

Charles

  • The current wave of AI-accelerated breaches is “just the very beginning” as most companies’ security budgets and threat models haven’t caught up to how cheap attacks have become, so the transition period will stay “bumpy.”
  • Given sufficient investment, security-by-design practices such as formal verification, cryptography by default, and zero-trust architecture will become the norm, helped by AI giving defenders what Charles calls “effectively infinite” security-research capacity.
  • Looking roughly ten years out, Charles expects systems overall to be “incredibly more secure than today,” potentially re-establishing the attacker/defender asymmetry that AI currently threatens.
  • Nation-states will increasingly treat frontier AI models as cyberweapons; Charles hopes for something like the deterrence norms that emerged around nuclear weapons, while acknowledging real uncertainty about whether that happens.

Reading List

Learn more about these topics mentioned in the episode, or explore our library of articles on Ledger Academy:

Stay in touch

Announcements can be found in our blog. Press contact:
[email protected]

Subscribe to our
newsletter

New coins supported, blog updates and exclusive offers directly in your inbox


Your email address will only be used to send you our newsletter, as well as updates and offers. You can unsubscribe at any time using the link included in the newsletter. Learn more about how we manage your data and your rights.