An attack on Coldcard hardware wallets could have been prevented by checking the code with artificial intelligence for $2. This was stated by Dragonfly venture fund managing partner Haseeb Qureshi.
People are not appreciating one of the biggest takeaways from the COLDCARD hack.
— Haseeb >|< (@hosseeb) August 3, 2026
Cybersecurity is now all about spend. Once AIs are doing all of the attacking, the simple question is how much money are you spending with frontier AIs scanning for vulnerabilities, compared to what... https://t.co/jkljyYtkxr
Cybersecurity has boiled down to a question of expenditure, the expert believes. Vulnerability discovery on the attackers' side is now handled by AI models, so a product's security is determined by how much the developer spends on scanning its own code with similar tools — compared to the spending of the attacking side.
According to Qureshi's logic, the speed at which a neural network discovers a known bug serves as an indirect indicator of the cost to preemptively fix it. He applied this thesis to Coinkite, based on reports of Claude's eight-minute success with Coldcard. However, the Dragonfly partner considered the result dubious — the model could have used a published description of the problem.
In response, another user ran a test on $GLM 5.2 without internet access: the time increased to 20 minutes. Qureshi converted this into a monetary equivalent based on the API rates of Zhipu AI (the developer of $GLM): $1.4 per million input tokens and $4.4 per million output tokens. He tasked the Opus model with the calculation, which estimated the total cost at approximately $2.
"A $2 AI-powered security boost would have caught the [Coldcard] vulnerability," concluded Qureshi.
Losses Grow to $100 Million
According to Galaxy Research, at least 15 different malicious actors exploited the vulnerability. Analysts came to this conclusion after processing new reports from victims — unlike a hack of a centralized exchange where the scale is immediately visible, the picture here formed gradually.
now NUMEROUS different attackers exploiting the Coldcard vulnerability. we estimate at least 15 different attackers now
— Alex Thorn (@intangiblecoins) August 4, 2026
we continue to receive victim reports and give them info to report to authorities
and those reports help us identify new attacks and label attackers https://t.co/6ybBTqJPb6
"Thanks to one victim reporting a theft of less than 1 $BTC, we discovered a new attack that withdrew 12 $BTC from 126 addresses," wrote the firm's Head of Research, Alex Thorn.
Galaxy Research estimated losses from the three confirmed waves at $100 million. Including a suspected fourth wave, the total could rise to approximately $130 million.
Recall that on the night of July 31, approximately 500 Coldcard owners had 594.48 $BTC stolen. After the news broke, holders began transferring bitcoins to new addresses, not to exchanges, Glassnode analysts noted.
On August 4, Trezor and Foundation warned users about phishing campaigns in light of the incident.
Sleep at Night Technology: How Coldcard Turned Its Users' Sleep into a Nightmare





