Haseeb Qureshi, a managing partner at Dragonfly, said this week that a vulnerability in Coldcard's hardware wallet could have been caught by an AI-powered audit costing as little as $10. The comment came during a discussion about how artificial intelligence is reshaping the economics of crypto security.
The Coldcard vulnerability
Coldcard, a popular Bitcoin hardware wallet, disclosed a flaw earlier this year that could allow an attacker with physical access to extract seed phrases. The bug was serious enough that the company issued an urgent firmware update. Qureshi's point: the kind of analysis that found it is now cheap enough that any project can run it.
“A $10 AI audit could have caught the Coldcard vulnerability,” Qureshi said. He argues that AI is rewriting the economics of cybersecurity by drastically reducing the cost of finding flaws. Traditional manual code reviews can cost thousands of dollars per engagement. Frontier AI models, he says, can do the same work for pocket change.
What Qureshi recommends
Qureshi, a general partner at Dragonfly, didn't stop at the Coldcard example. He urged crypto companies to integrate frontier AI models into their development pipeline. “Crypto companies should use frontier AI models to test every software release,” he said. The idea is to catch bugs before they reach production, not just after a post-mortem.
His recommendation comes as the industry grapples with a steady drumbeat of hacks and exploits. In 2026 alone, several DeFi protocols have lost millions to smart contract bugs. Qureshi's argument is that the cost of prevention has dropped so low that skipping an AI audit is no longer defensible.
The economics of security have always been a barrier for smaller teams. A full audit from a top firm can run $50,000 or more. That's out of reach for many early-stage projects. If Qureshi is right, AI tools could democratize access to security testing. A $10 check per release changes the math entirely.
Of course, not everyone is convinced that AI audits are a replacement for human review. But Qureshi isn't arguing for replacement — he's arguing for a baseline. “You can still hire humans for the deep stuff,” he said. “But there's no excuse for not running an AI pass first.”
Dragonfly hasn't announced any specific product or investment tied to AI security audits. But Qureshi's public stance signals that the firm sees this as a major trend. Expect more crypto VCs to start asking portfolio companies whether they're running AI tests on every commit. The question may soon become standard due diligence.




