#146 AI Found What Nine Years of Security Research Missed with Charles Guillemet // CTO @ Ledger
Vor 2 Tagen•54:24
Charles Guillemet has spent nine years building Ledger's security organization from scratch — first as the founder of The Donjon, Ledger's in-house offensive security research team, then as CTO overseeing security for a company safeguarding roughly 20% of the world's crypto (per Tobi's intro framing). The conversation centers on one uncomfortable observation: with the latest generation of frontier AI models, Ledger's researchers started finding product vulnerabilities that fifteen dedicated experts hadn't found in nine years of trying. Charles explains why this matters security has always relied on an economic asymmetry between what it costs to attack a system and what an attacker stands to gain, and AI is collapsing that asymmetry by driving the cost of finding a vulnerability toward zero. From there, Tobi and Charles dig into what actually holds up: security-by-design, treating security as a key-management problem, zero trust, and for teams rebuilding their SDLC around AI — Charles's recommendation of small, AI-native pods spending most of their time on "harness engineering" rather than writing code. They also cover why he believes the CISO function should stay organizationally independent, even though it reports to him at Ledger today.