Cryptocurrency Companies Urged to Report AI-Driven Vulnerability Costs
Dragonfly's managing partner Haseeb Qureshi has proposed that cryptocurrency companies report the 'cost of discovery' - the amount spent by AI models to find vulnerabilities.
This comes after a recent vulnerability was discovered in the COLDCARD, a hardware wallet for Bitcoin. The weakness allowed attackers to predict random numbers used for seed phrase generation, making it possible for them to access user funds.
The COLDCARD's developer, Coinkite, released a security advisory on July 30 and issued an update with new firmware and instructions for users to migrate their assets to a new wallet.
Qureshi noted that AI model Claude Code was able to find the vulnerability in just 8 minutes, but pointed out that this could be because it referenced publicly available information. To confirm, another Reddit user ran the same test with GLM 5.2 and found the issue in about 20 minutes.
Qureshi estimated the cost of discovery for this specific vulnerability to be around $2, based on data from ZhipuAI's API pricing and processing costs. He argued that companies should report the 'cost of discovery' when a vulnerability is independently reproduced, and suggested that this could help prevent attacks by making it clear how much money was spent searching for vulnerabilities.