The AI hacking era is here: what Hoskinson's warning means for how you hold crypto

Reviewed by Updated July 24, 2026

Based on verified official data as of 24.07.2026; hands-on update coming.

In a July 2026 Markets Outlook interview, Cardano founder Charles Hoskinson said the industry has entered the age of AI hacking: frontier models are being used to attack software at scale, more Linux kernel vulnerabilities surfaced in the past two months than in the prior two years, and his own ecosystem took a bridge hack that same week. His prescription is structural — zero-knowledge proofs instead of trusted operators, identity you can prove without KYC-style disclosure, and opt-in insurance for wallets and bridges. For anyone holding crypto on cards and wallets today, the practical takeaway is blunter: assume any single piece of software can fail, and structure your custody so one failure is never a total loss.

TL;DR

  • Hoskinson's claim, from the interview: more Linux kernel vulnerabilities were discovered in the last two months than the previous two years — AI models are industrialising the search for exploits.
  • The trigger was concrete: a legacy third-party bridge on the Binance-Cardano side was hacked the Monday before the interview, with stolen tokens dumped on the market.
  • His fix is 'trust the math': zero-knowledge systems replace trusted bridge operators and multisigs; Midnight Passport pairs identity with a wallet via selective disclosure — proof of ownership without handing over documents.
  • Wallet and bridge insurance is coming: opt-in premiums pooled as a real-world asset, payouts on verified hacks — and insurability forces wallets and bridges to meet best-practice standards.
  • Until that arrives, the defence is architectural: self-custody for reserves, spending-size balances on any card or platform, and no single point of failure holding more than you can lose.

What Hoskinson actually said, and why the week made his point

The interview opened with an admission most founders would bury: that Monday, a bridge on the Binance-Cardano side was hacked and the stolen tokens dumped. Hoskinson's framing was structural rather than defensive — the bridge was a legacy system built by a third-party company, exactly the class of trusted middleware he has spent years arguing should not exist. In his words, the industry got a fresh 'example of the need for maturing'.

The wider claim is the one worth sitting with: AI models are now doing the vulnerability hunting. He cited the Linux kernel — more flaws discovered in the past two months than the prior two years — as evidence that all software, not just crypto, is under an assault that scales with compute. High-assurance systems fare better, he argued, but being '90% resistant to a deadly disease' is no comfort when exposure is constant. Speed-to-market, the industry's favourite virtue, is quietly becoming a liability.

Charles Hoskinson speaking on stage at Consensus 2026
Photo: Charles Hoskinson at Consensus 2026. By Xuthoria, Wikimedia Commons, CC BY-SA 4.0.

Trust the math: the ZK answer to trusted operators

Hoskinson's engineering answer is zero-knowledge proofs — moving from 'trust a bridge operator or trust a multisig' to verifying a mathematical proof. His Midnight project applies the same primitive to identity: Midnight Passport pairs a person with a wallet through selective disclosure, so you can prove a wallet is yours — to an insurer, an arbitrator, a recovery process — without surrendering the document bundle a custodial KYC flow demands.

That distinction lands close to home for this site's readers. We have written at length about the custody-versus-KYC trade — our non-custodial cards guide maps the quadrants — and selective disclosure is effectively a third option the current market does not offer: identity that activates only when something goes wrong. It also enables what Hoskinson called the dead-man switch: pre-authorised sweeps of a wallet to a recovery path if you lose access, die, or, in his cheerful example, spend a decade in a foreign prison.

Wallet insurance: the unsexy product that changes behaviour

The most concrete proposal in the interview was insurance for wallets and bridges. The mechanics he sketched: opt-in coverage, paid monthly or per-transaction into a pool structured as a real-world asset; collateral providers earn the premium while no claim triggers; verified hacks pay out. He had just returned from Bermuda, where the insurance regulator was actively discussing wallet, bridge and AI-agent coverage.

The second-order effect matters more than the payouts. Insurers do not write policies for warehouses without fences — so insurable wallets and bridges must meet defined best practices in governance, operations and software formalism. Insurance becomes the enforcement mechanism the industry never built for itself. Combined with the American Arbitration Association's new legal-context protocol — which could let users pre-consent to licensed white-hat rescues during an active attack — the picture is a financial system growing rule of law, not just cryptography.

Until those products exist, the absence of a safety net is itself the risk model. Our no-KYC card risks ranking and the card-death playbook both rest on the same premise Hoskinson conceded: today, when a wallet or program dies, 'you lost all your money, too bad, move on' — so position sizes, not promises, are your insurance.

Layer of the fixWhat it replacesStatus per the interview
ZK proofs for bridgesTrusted operators and multisigsGroth16 verification live on Cardano after the v11 hard fork
Midnight Passport (selective disclosure)Full custodial KYC or total anonymityIn development; core to insurance and recovery flows
Wallet/bridge insurance poolsNothing — total-loss status quoRegulator discussions (Bermuda BMA); products not yet on market
Legal-context protocol (AAA)Legal grey zone for white-hat rescuesAnnounced; privacy standard still missing

Web 2.5 and the custody spectrum ordinary users actually need

Hoskinson's market thesis is that neither pole of today's custody choice works for most people. Custodial means 'you completely hope that entity is going to treat you right'; non-custodial means any failure, including software bugs that are not your fault, is a total loss. Both, in his words, are untenable for 95% of consumer use cases. The growth he points to — stablecoin issuers, regulated exchanges, payment rails — is all 'web 2.5': regulated companies connected to blockchain products, with the consumer choosing their level of protection.

That spectrum is precisely what the crypto card market already looks like from the user's side: custodial exchange cards at one end, self-custody spending like Jam at the other, and the real decision being how much platform risk you accept per pocket of money. His prediction that abstraction plus insurance plus identity will let users dial protection per transaction is, in effect, the two-rail setup this site recommends — formalised into products.

What to do with this today, without waiting for Midnight

Strip the ecosystem politics and the interview yields four defensible moves. One: treat bridges as the highest-risk surface in crypto — the interview's own news cycle proved the point — and avoid parking value in bridged form. Two: keep reserves in self-custody and spending money in spending-size amounts, because the total-loss regime is still the law of the land; our privacy-stack guide covers the wallet discipline. Three: prefer platforms and cards with visible security engineering over fastest-to-market features — in the AI hacking era, boring is a feature. Four: watch for wallet insurance products; when they arrive, insurability will be the fastest quality signal the industry has ever had.

And his market outlook, for context on timing: fear-and-greed near 24, roughly 50% below the $4.4 trillion peak, three to six more months of pain expected, with the CLARITY act a potential sugar-high rather than a fix. Whether or not the price call lands, the security argument stands on its own — the attack side just got industrialised, and the defence side is still shipping.

Risk warning: derivatives and crypto-backed credit involve significant risk, including liquidation of your collateral. Never commit funds you cannot afford to lose. Nothing on this page is financial, investment or tax advice.

Who this is NOT for

  • Anyone reading this as investment advice or an ADA endorsement — it is an analysis of security arguments from one founder's interview, with the ecosystem advocacy left at the door.
  • Readers expecting wallet insurance to exist today — the products discussed are in regulator-conversation stage, not on the market.
  • Anyone treating ZK identity as a way to avoid tax obligations — selective disclosure changes who sees your documents, not what you owe (see our DAC8 guide).
  • Users looking for a reason to abandon self-custody — the interview argues for better safety nets around it, not for going back to custodians.

Frequently asked questions

Hoskinson's claim is that frontier models are industrialising vulnerability discovery across all software, citing the Linux kernel spike and naming AI models as the driver. The bridge hack that week was a legacy-software failure — consistent with the thesis that the oldest, most trusted-operator-dependent components break first.

NomadCrypto Editor

Editorial Team, NomadCard

The NomadCrypto editorial team verifies every published fee across 59 crypto cards against issuer documentation, with the verification date shown on every figure.