Dragonfly's Haseeb Qureshi: A $2 AI Audit Could Have Flagged the Coldcard Seed Bug

AI Market Summary
Dragonfly's Haseeb Qureshi argues a Coldcard firmware entropy flaw, reportedly reproducible by frontier AI for about $2 in minutes, signals a step-change in security economics for crypto products. If vulnerability discovery costs collapse, wallet makers and protocol teams may need continuous AI-based testing on every release, advantaging larger firms with bigger security budgets. Near-term, the news raises operational and reputational risk awareness across crypto custody.
Impact level
● Medium
Affected assets
BTC/USDT+1.08%
AI Insight · BTC/USDTAI Insight
● Neutral
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Dragonfly managing partner Haseeb Qureshi says a recently disclosed Coldcard vulnerability underscores how AI is reshaping the economics of cybersecurity. With the cost and time required to surface software flaws falling sharply, Qureshi argues crypto companies should run frontier AI model checks on every release. Coldcard disclosed an entropy issue affecting seeds generated on certain firmware versions. The flaw could cause some devices to draw randomness from a deterministic software generator instead of the intended hardware entropy source. Coinkite shipped emergency firmware updates on July 31 and advised impacted users to generate new seeds and move funds, noting that updating firmware alone does not fix an already-created seed. According to reports cited by Qureshi, an AI-assisted test rediscovered the vulnerability quickly. One attempt using Anthropic's Claude Code surfaced the bug in about eight minutes. Qureshi noted the result may have been influenced by internet access that could have exposed the model to existing information about the issue. In a separate run with web access disabled, GLM 5.2 reproduced the vulnerability in roughly 20 minutes. Based on input and output costs, Qureshi estimated the audit expense at about $2, writing on X: "$2 of AI hardening would’ve caught this bug. There is no excuse for this." He added that "cybersecurity is now all about spend," framing the core question as how much developers invest in AI-based testing versus what attackers are willing to spend. Qureshi also proposed a new metric, "Cost of Discovery" (CoD), intended to estimate how much it costs a frontier AI model to independently reproduce a vulnerability. He suggested the incident could reshape competitive dynamics in the hardware wallet market. Larger vendors, he argued, may gain an edge by funding more continuous automated testing, audits, and release hardening. Smaller companies could find it harder to keep pace as attackers can scan code at minimal cost. Qureshi urged startups building wallets, smart contracts, and other products that safeguard funds to run AI security reviews before every release. He also pushed back on the notion that open-source code is automatically safer: public code can help protect users from malicious developers, he said, but it does not inherently protect against attackers—especially as AI tools can benefit both sides. "We have no choice but to adapt," he wrote.