Cerberus: Why Ledger Is Preparing for a New Age of AI-Powered Cyberattacks

This content includes affiliate links for Ledger products. If you purchase through these links, we earn a commission at no extra cost to you. This is not financial advice. Cryptocurrency assets carry high risks, including the risk of losing your entire investment. Please do your own research and make decisions based on your personal risk tolerance.
A while ago, I caught myself doing something that would have sounded ridiculous only a few years earlier. I was asking Claude to examine a piece of code and tell me what was wrong with it.
Within seconds, it sorted things out.
That got me thinking. If a layman like me can use AI this easily, imagine what a skilled hacker can do with it.
A hacker no longer has to work entirely alone. AI can help read code, investigate unfamiliar software, generate scripts and repeatedly test ideas. Work that once consumed hours of human attention can potentially be accelerated dramatically.
That creates an uncomfortable question for anyone protecting valuable digital assets.
What happens when hackers start attacking at machine speed?
Ledger Donjon, Ledger's security research team, has been working on an answer.
It's called Cerberus.
Cerberus: Why Ledger Is Preparing for a New Age of AI-Powered Cyberattacks: What Exactly Is Cerberus?
Ledger describes it as an AI security harness.
Instead of simply asking an AI chatbot whether some code looks secure, Cerberus gives AI agents jobs, tools and processes that allow them to investigate potential vulnerabilities much more deeply.
Think of a traditional security researcher.
They examine a system. They notice something suspicious. They test it. They try to reproduce the problem. They determine whether someone could actually exploit it. Then they work out how the vulnerability should be fixed.
Cerberus tries to accelerate that entire process with AI.
Ledger says the system can help security researchers explore, challenge, verify and patch vulnerabilities. Humans remain involved, but AI can perform repetitive investigative work at a scale that would be difficult for a human team alone.
This distinction matters. Cerberus isn't simply an AI model.
It's the system surrounding the models.
Why AI Changes the Hacking Game
Cybersecurity has always involved a race. Someone discovers a weakness. Someone else fixes it. Attackers search for another route. AI could make that cycle dramatically faster.
Imagine giving an AI agent access to a large software project and asking it to search for weaknesses.
The AI doesn't get tired. It doesn't need coffee. It doesn't mind checking thousands of possibilities. Most of those investigations might lead nowhere. That doesn't necessarily matter when the cost of trying another approach keeps falling.
Ledger Donjon argues that AI changes the economics of offensive security because it can reduce costs, increase scale and automate parts of vulnerability exploration. That doesn't mean AI suddenly turns everyone into an elite hacker.
Expertise still matters. But a knowledgeable attacker equipped with powerful AI tools could become considerably more productive.
Security teams therefore need similar tools.
Cerberus Is More Than One AI Agent
Ledger initially experimented with the idea of an autonomous penetration-testing agent. The early version didn't magically become a brilliant hacker. It stopped after a few minutes without producing anything particularly useful. Ledger learned an important lesson.
A prompt isn't an agent.
A useful security agent needs memory. It needs tools. It needs to know what it has already tested. It needs a list of things to investigate next. It also needs another system capable of questioning its conclusions.
Cerberus gradually developed into a team of specialised AI agents.
Striker concentrates on offensive exploration and penetration-testing-style work. Sentinel focuses on reviewing code. Jarvis helps organise, challenge and prioritise potential vulnerabilities. Hopper assists with deeper investigation. Vecna tries to determine whether a suspected weakness can actually be exploited. Merlin works on fixing vulnerabilities.
The names are colorful, but the structure behind them is serious. One AI can question another.
That is important because AI makes mistakes.
Finding a Bug Isn't Enough
Imagine an AI examines some software and announces: "I found a critical vulnerability."
That sounds alarming.
But is it really vulnerable? Can the problem actually be reproduced? Can an attacker exploit it? What conditions would be required? Could the AI simply have misunderstood the code?
These questions separate an interesting observation from a useful security finding. Cerberus is designed to push investigations further. Ledger says potential findings can be challenged, scanned again and tested for exploitability. Proposed patches can then be reviewed again to determine whether the original vulnerability has really been removed.
Humans remain in the loop. That combination is important. AI provides speed.
Humans provide judgement.
Cerberus Is Already Finding Real Vulnerabilities
This isn't purely a research concept. Ledger Donjon says Cerberus has already helped uncover exploitable vulnerabilities in outside projects. Its published examples include issues affecting Sandboxie-Plus, Yubico software, KDE Kleopatra, Nethermind, Wasabi Wallet and BTCPay Server. Ledger says realistically exploitable findings are reported privately through responsible disclosure processes.
That provides an early indication of what AI-assisted security research could become.
Instead of waiting for attackers to discover weaknesses, security researchers can use AI to behave more like attackers themselves.
Find the weakness. Try to break it. Prove that the attack works.
Then fix it.
Why This Matters for Crypto Owners
For most software, a security vulnerability is annoying. For cryptocurrency, the consequences can be much worse.
Crypto ownership ultimately depends on cryptographic keys. If those keys are compromised, blockchain transactions generally cannot simply be reversed by calling a bank.
This is one reason dedicated hardware signers exist. Ledger's current devices use Secure Elements and secure displays or inputs as part of their protection architecture. Ledger Donjon also continuously researches attacks against hardware, firmware and software rather than treating security as something that ends when a product ships.
Cerberus adds another layer to that philosophy.
Attack your own systems. Look for problems. Keep testing.
And increasingly, let AI help.
Choosing a Ledger for the AI Security Era
Better security research doesn't remove the need for good personal security habits. If you hold meaningful amounts of cryptocurrency, keeping private keys away from an ordinary internet-connected computer remains one of the most practical steps you can take.
Ledger currently offers five main signers for different types of users.
Ledger Stax is the premium option. Its large 3.7-inch curved E Ink secure touchscreen gives you considerably more space to review what you're signing. It's designed for people who want security without making their hardware feel like a purely technical tool.
Ledger Flex brings the secure touchscreen concept into a smaller format. Its 2.8-inch E Ink touchscreen provides a clear way to review transactions while keeping the device compact enough for regular use.
Ledger Nano Gen5 brings a 2.8-inch secure E Ink touchscreen to the Nano family. It supports USB-C, Bluetooth and NFC, plus features including Clear Signing, Transaction Check and passkeys. A Ledger Recovery Key is also included for optional PIN-protected backup and restoration.
Ledger Nano X remains a practical choice for mobile users who prefer the familiar Nano design. It includes Bluetooth and a built-in battery, making it convenient for people who manage crypto while travelling.
Ledger Nano S Plus keeps things simpler. It's a USB-C, button-operated signer without the wireless emphasis of the newer devices. That simplicity can make it particularly attractive as a home device or backup signer.
The best choice isn't necessarily the most expensive one. It's the device that matches how you actually manage your crypto.
AI Versus AI May Become the New Cybersecurity Reality
Cerberus points toward something much bigger than Ledger. We're entering a period when both sides of cybersecurity have access to increasingly capable AI.
Attackers can use AI to explore. Defenders can use AI to explore too. Attackers can automate testing. Defenders can automate testing. Attackers can search enormous amounts of code. Defenders can do exactly the same thing.
The difference may increasingly come down to who builds the better system around the AI. That is perhaps the most interesting lesson from Cerberus. Ledger discovered that simply giving an AI a prompt wasn't enough. Effective AI security requires tools, memory, repeated testing, specialized agents, verification and human oversight.
In other words, the future probably isn't AI replacing security researchers. It's security researchers commanding small armies of AI agents.
The Cat-and-Mouse Game Just Got Faster
Cerberus: Why Ledger Is Preparing for a New Age of AI-Powered Cyberattacks: Cybersecurity has always been a cat-and-mouse game.
AI hasn't changed that basic relationship. It has changed the speed.
A vulnerability that once required days of investigation might eventually be discovered much faster. An attacker who once had time to examine one target could potentially investigate many.
That sounds frightening. But there's another side to it. Defenders get the same technology. Cerberus shows what happens when AI isn't merely asked to explain security but is built into the actual process of finding, proving and fixing vulnerabilities.
For crypto owners, that matters. The technology protecting our digital assets cannot stand still while the technology attacking them improves.
The next generation of cyberattacks may arrive at machine speed. The encouraging part is that the next generation of cyber defence is learning to move at machine speed too.








Comments