AI-Powered Security Testing: A New Metric for Crypto Companies
The discovery of a vulnerability in the Coldcard hardware wallet has highlighted the growing importance of artificial intelligence (AI) in crypto security, according to Dragonfly Managing Partner Haseeb Qureshi.
Qureshi proposed a new metric called Cost of Discovery, which estimates how inexpensively a frontier AI model can reproduce a software vulnerability. He applied this concept to the Coldcard flaw and estimated its discovery cost at roughly $2.
The discussion around the Coldcard vulnerability also touched on the role of web search capabilities in AI-powered security testing. Qureshi noted that Anthropic's Claude Code identified the issue in about eight minutes, but he suggested that this may have been due to its access to web search capabilities rather than its actual AI abilities.
In comparison, an offline test using the GLM model reproduced the same issue in approximately 20 minutes. This difference highlights the potential benefits of investing in AI-powered security testing for companies looking to improve their product safety.