
Dragonfly managing partner Haseeb Qureshi said a recently disclosed Coldcard wallet vulnerability illustrates how artificial intelligence is reshaping cybersecurity economics in crypto. As the cost of finding software flaws falls, he argued, companies should run cutting-edge AI model audits on every release to keep pace with increasingly automated attackers.
AI Is Lowering the Cost of Vulnerability Discovery
Qureshi said the Coldcard issue highlights a broader shift: state-of-the-art AI systems can accelerate code review, static analysis, and test generation, enabling faster and cheaper discovery of defects. That dynamic, he noted, changes the balance between attackers and defenders, increasing pressure on teams to detect issues earlier in the development cycle.
The rise of AI-assisted security tooling is expanding the surface and speed of testing across codebases, firmware, and build pipelines. In practice, this means more frequent disclosures and shorter windows between introduction and detection of bugs, raising the bar for release readiness and post-release monitoring.
Call for AI Audits on Every Software Release
Qureshi urged crypto companies to integrate frontier AI models into continuous integration and pre-release checks, treating them as a standard control alongside human audits, open-source review, fuzzing, and traditional static/dynamic analysis. The goal, he said, is to make AI-driven code and firmware scanning a routine gate before shipping any update.
Applying AI consistently across releases can help catch edge cases, supply chain anomalies, and regression risks that may elude manual review, especially in complex wallet firmware, node software, and smart contract systems.
Why It Matters for Wallets and Critical Infrastructure
Hardware wallets such as Coldcard, developed by Coinkite, safeguard private keys used to authorize blockchain transactions. Vulnerabilities in these devices or their firmware can undermine signing integrity and erode user trust. Because crypto systems are adversarial by design and operate on immutable ledgers, preventative controls and rapid detection carry outsized importance.
Background and Industry Context
Dragonfly is a crypto-focused venture capital firm; Qureshi is known for commentary on security and market structure. His remarks arrive as AI-enhanced security testing becomes more common across the software industry, with vendors and open-source teams pairing automated tools with human-led reviews to reduce time-to-discovery and remediation costs.
The Coldcard case, Qureshi said, serves as a timely reminder that the economics of vulnerability discovery are shifting—and that defenders must adapt their release processes accordingly.