AI Finds Vulnerability Behind $100M Bitcoin Theft in Just 20 Minutes
An AI model reportedly needed about 20 minutes and $2 to rediscover the vulnerability linked to the recent ColdCard theft, according to a test conducted by Dragonfly managing partner Haseeb Qureshi.
The GLM 5.2 experiment demonstrated that attackers and developers can now examine code protecting large amounts of cryptocurrency at a low cost.
Qureshi emphasized the significance of the $2 cost, stating that it marks 'a new world' where even inexpensive models can be used for security research.
The test did not establish that AI was involved in the theft, but rather showed how cheaply attackers and developers can now review old wallet code and cryptographic implementations repeatedly.
Researchers can assign multiple models to a single codebase, ask them to investigate different failure paths, and repeat the process whenever a stronger model becomes available.