Dragonfly’s Haseeb Qureshi says the Coldcard vulnerability shows how artificial intelligence (AI) is rewriting cybersecurity economics. As the cost of finding flaws collapses, he argues that crypto companies must deploy frontier AI models against every software release.
Key Takeaways
Coldcard fixed a seed flaw on July 31 after AI reportedly found it in 8 minutes.Haseeb Qureshi says $2 AI audits could favor crypto firms with deeper security budgets.Qureshi urged frontier AI checks on every release as flaw discovery falls to minutes.Artificial intelligence is making vulnerability discovery so cheap that security may increasingly depend on how much companies are willing to spend before attackers do.
Based on the model’s input and output costs, he estimated that the audit cost about $2. “$2 of AI hardening would’ve caught this bug. There is no excuse for this,” he remarked. Qureshi proposed a new measure called Cost of Discovery, or CoD. The metric would estimate how much it costs a frontier AI model to independently reproduce a vulnerability.
Smaller Security Vendors Face Growing PressureThe episode may have wider consequences for the hardware wallet market.
Qureshi argued that larger vendors will have an advantage because they can spend more on automated testing, audits, and release hardening. Smaller companies may struggle to match attackers who can scan code continuously at little cost.
Startups building wallets, smart contracts or other products that protect money should run AI security reviews before every release, he recommended.
Qureshi also challenged a common assumption about open-source security. Public code can protect users from malicious developers, he said, but it does not automatically protect them from attackers.
AI can serve both sides. It lowers the price of finding vulnerabilities, but it also gives developers stronger defensive tools.
“We have no choice but to adapt,” Qureshi said.

















