AI Finds Flaw in Coldcard Firmware for Just $2
A recent vulnerability in Coldcard's bitcoin wallet firmware has exposed how artificial intelligence (AI) is revolutionizing cybersecurity economics. According to Dragonfly managing partner Haseeb Qureshi, $2 AI audits could have caught this flaw within minutes.
The bug, which affected seeds created with certain firmware versions, caused some devices to rely on a deterministic software generator instead of the intended hardware source of randomness. Coinkite released emergency updates on July 31 and advised affected users to create new seeds and move their funds.
Qureshi estimated that an AI audit costing around $2 could have independently reproduced the vulnerability, and proposed a new metric called Cost of Discovery (CoD) to estimate how much it costs a frontier AI model to reproduce a vulnerability.
He warned that smaller security vendors face growing pressure due to larger vendors' ability to spend more on automated testing, audits, and release hardening. Qureshi urged startups building wallets or other products that protect money to run AI security reviews before every release.