According to Haseeb Qureshi, managing partner at venture capital firm Dragonfly, a mere $2 spent on AI code inspection could have prevented the Coldcard wallet hack.
People are not appreciating one of the biggest takeaways from the COLDCARD hack.
Cybersecurity is now all about spend. Once AIs are doing all of the attacking, the simple question is how much money are you spending with frontier AIs scanning for vulnerabilities, compared to what… https://t.co/jkljyYtkxr
— Haseeb >|< (@hosseeb) August 3, 2026
Qureshi believes that cybersecurity has become a matter of financial investment. With AI models now capable of probing for vulnerabilities, the security of a product is largely determined by how much developers invest in scanning their own code using similar AI tools compared to the resources allocated by attackers.
He argues that the speed at which a neural network identifies a known flaw indirectly indicates the costs associated with its preventive measures. Qureshi applied this reasoning to Coinkite, referencing reports of the AI model Claude successfully exploiting Coldcard's vulnerability in eight minutes. However, he expressed skepticism about this result, suggesting that the model might have leveraged publicly available information about the issue.
In response, another user conducted a test using GLM 5.2 without internet access, which extended the detection time to 20 minutes. Qureshi translated this time into a monetary equivalent based on the API rates from Zhipu AI (the developer of GLM): $1.4 for every million input tokens and $4.4 for every million output tokens. He utilized the Opus model for this calculation, which approximated the total costs at around $2.
“Strengthening security with AI at a cost of $2 would have caught the [Coldcard] vulnerability,” Qureshi concluded.
Damage Estimated at $100 Million
Galaxy Research reports that at least 15 different attackers exploited the vulnerability. Analysts reached this conclusion by processing new victim reports, noting that unlike centralized exchange hacks where the scale is immediately visible, this situation unfolded gradually.
now NUMEROUS different attackers exploiting the Coldcard vulnerability. we estimate at least 15 different attackers now
we continue to receive victim reports and give them info to report to authorities
and those reports help us identify new attacks and label attackers https://t.co/6ybBTqJPb6
— Alex Thorn (@intangiblecoins) August 4, 2026
“Thanks to one victim's report of the theft of less than 1 BTC, we identified a new attack that withdrew 12 BTC from 126 addresses,” stated Alex Thorn, head of research at the firm.
Galaxy Research estimates losses from three confirmed waves at $100 million, with potential for the total to rise to approximately $130 million considering a suspected fourth wave.
It is important to note that on the night of July 31, around 500 Coldcard users lost 594.48 BTC. Following the incident, holders began transferring their bitcoins to new addresses rather than exchanges, as observed by analysts at Glassnode.
On August 4, Trezor and Foundation issued warnings about phishing attempts in light of the incident.