{"slug": "dragonfly-s-haseeb-qureshi-says-2-ai-audit-could-have-caught-coldcard-flaw", "title": "Dragonfly's Haseeb Qureshi Says $2 AI Audit Could Have Caught Coldcard Flaw", "summary": "Dragonfly managing partner Haseeb Qureshi said a $2 AI audit could have caught a critical entropy flaw in Coldcard bitcoin wallet firmware, which Coinkite disclosed and patched with emergency updates on July 31. Qureshi proposed a new metric called Cost of Discovery (CoD) to estimate how much it costs a frontier AI model to independently reproduce a vulnerability, warning that cybersecurity is now about spending and that smaller security vendors face growing pressure.", "body_md": "## Coldcard Flaw Could Push Crypto Firms to Test Every Release With AI\n\nArtificial intelligence is making vulnerability discovery so cheap that security may increasingly depend on how much companies are willing to spend before attackers do.\n\nThat is the warning from Dragonfly managing partner Haseeb Qureshi after AI models reportedly rediscovered a critical weakness in Coldcard’s bitcoin wallet firmware within minutes.\n\n“Cybersecurity is now all about spend,” Qureshi wrote on X. The key question, he said, is how much developers invest in AI-based testing compared with potential attackers.\n\nColdcard disclosed an entropy flaw affecting seeds created with certain firmware versions. The bug caused some devices to rely on a deterministic software generator instead of the intended hardware source of randomness. Coinkite released emergency updates on July 31 and told affected users to create new seeds and move their funds. Installing new firmware alone does not repair an old seed.\n\n## Vulnerability Was Reportedly Found Within Minutes\n\nOne test reportedly found the flaw with Anthropic’s Claude Code after about eight minutes. Qureshi cautioned that the result may have been influenced by internet access, which could have exposed the model to existing information about the bug. A separate test disabled web access and used GLM 5.2. It reproduced the vulnerability in roughly 20 minutes.\n\nBased on the model’s input and output costs, he estimated that the audit cost about $2. “$2 of AI hardening would’ve caught this bug. There is no excuse for this,” he remarked. Qureshi proposed a new measure called Cost of Discovery, or CoD. The metric would estimate how much it costs a frontier AI model to independently reproduce a vulnerability.\n\n## Smaller Security Vendors Face Growing Pressure\n\nThe episode may have wider consequences for the hardware wallet market.\n\nQureshi argued that larger vendors will have an advantage because they can spend more on automated testing, audits, and release hardening. Smaller companies may struggle to match attackers who can scan code continuously at little cost.\n\nStartups building wallets, smart contracts or other products that protect money should run AI security reviews before every release, he recommended.\n\nQureshi also challenged a common assumption about open-source security. Public code can protect users from malicious developers, he said, but it does not automatically protect them from attackers.\n\nAI can serve both sides. It lowers the price of finding vulnerabilities, but it also gives developers stronger defensive tools.\n\n“We have no choice but to adapt,” Qureshi said.", "url": "https://wpnews.pro/news/dragonfly-s-haseeb-qureshi-says-2-ai-audit-could-have-caught-coldcard-flaw", "canonical_source": "https://cryptonews.net/news/security/33248744/", "published_at": "2026-08-05 03:57:00+00:00", "updated_at": "2026-08-05 05:11:50.053176+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-tools"], "entities": ["Dragonfly", "Haseeb Qureshi", "Coldcard", "Coinkite", "Anthropic", "Claude Code", "GLM 5.2"], "alternates": {"html": "https://wpnews.pro/news/dragonfly-s-haseeb-qureshi-says-2-ai-audit-could-have-caught-coldcard-flaw", "markdown": "https://wpnews.pro/news/dragonfly-s-haseeb-qureshi-says-2-ai-audit-could-have-caught-coldcard-flaw.md", "text": "https://wpnews.pro/news/dragonfly-s-haseeb-qureshi-says-2-ai-audit-could-have-caught-coldcard-flaw.txt", "jsonld": "https://wpnews.pro/news/dragonfly-s-haseeb-qureshi-says-2-ai-audit-could-have-caught-coldcard-flaw.jsonld"}}