AI Model Finds Vulnerability Behind $100 Million Bitcoin Theft
A recent experiment using an AI model called GLM 5.2 has demonstrated that it can rediscover vulnerabilities in cryptocurrency software at a relatively low cost. In this case, the model was able to find a bug linked to the $100 million ColdCard theft after just 20 minutes and for only $2.
The test was conducted by Dragonfly managing partner Haseeb Qureshi, who stated that the experiment showed how cheaply attackers and developers can now examine code that protects large amounts of cryptocurrency. The model was not searching blindly across every hardware wallet or discovering an attack without a starting point; it was directed toward the affected software after the ColdCard incident had already focused attention on it.
Qureshi emphasized that identifying a bug is different from exploiting it at scale, and that attackers may still need to determine which devices or wallets are affected, reconstruct usable private keys, identify wallets containing valuable balances, and move funds before users or manufacturers can respond. The experiment establishes that a general-purpose model can quickly and at negligible cost rediscover the underlying technical weakness.