
Dragonfly managing partner Haseeb Qureshi says the Coldcard entropy flaw could have been caught with an $2 AI audit, warning that cybersecurity is now a spending race.
The Coldcard vulnerability could have been caught by an artificial intelligence audit that cost roughly $2, Dragonfly managing partner Haseeb Qureshi said. He warned that cybersecurity is becoming a spending race as the price of finding flaws collapses.
Coldcard, a hardware wallet for bitcoin made by Coinkite, disclosed an entropy flaw affecting seeds created with certain firmware versions. The bug caused some devices to rely on a software-based random number generator instead of the intended hardware source of randomness. Coinkite released emergency updates on July 31 and told affected users to create new seeds and move their funds. Installing new firmware alone does not repair an old seed.
One test using Anthropic's Claude Code reportedly found the vulnerability in about eight minutes. Qureshi cautioned that the result may have been influenced by internet access, which could have exposed the model to existing information about the bug. A second test used a model called GLM 5.2 with web access disabled. It reproduced the flaw in roughly 20 minutes. Based on the model's input and output costs, Qureshi estimated the audit cost about $2.
"$2 of AI hardening would've caught this bug. There is no excuse for this," he wrote on X. He proposed a new metric called Cost of Discovery, or CoD, which would estimate how much it costs a frontier AI model to independently reproduce a vulnerability.
The episode could reshape the hardware wallet market. Qureshi argued that larger vendors have an advantage because they can spend more on automated testing and release hardening. Smaller companies may struggle to match attackers who can scan code continuously at little cost. He recommended that startups building wallets, smart contracts or other products that protect money should run AI security reviews before every release.
Qureshi also challenged a common assumption about open-source security. Public code can protect users from malicious developers, he said, but it does not automatically protect them from attackers. AI serves both sides: it lowers the cost of discovering flaws, but it also gives developers stronger defensive tools.
"We have no choice but to adapt," Qureshi said.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.