Sixteen Bitcoin developers filed 4,962 security findings across 390 projects in under 30 hours, flagging 85 critical and 635 high-severity bugs in an AI-driven audit.
"Situation is extremely bad," Calle, the pseudonymous developer behind the Cashu ecash protocol who is coordinating the effort, said.
The volunteer group, dubbed the "Bitcoin Red Team," is running AI models including Kimi K3, GPT Sol, Fable, Opus and GLM5.2 against Bitcoin wallets, cryptographic libraries and infrastructure. The effort costs roughly $10,000 per day in compute, with more than $40,000 in AI tokens spent so far, funded by OpenSats, a nonprofit supporting open-source Bitcoin development. About 21.4 percent of findings have been reproduced with working proof-of-concept exploits, Calle said.
The audit lands days after the Coldcard hardware wallet exploit drained as much as $114 million from wallets whose seeds were generated by faulty firmware — a bug dormant since 2021 that required no physical access to the device once the affected key space was known. Attackers already have access to the same AI tools: Anthropic said in April that one of its models found a bug that had sat undiscovered in widely used software for 27 years at a cost of less than $50, and Google's threat intelligence team said in May it caught a criminal group preparing an attack built on a flaw a model had found for them.
Rob Hamilton, who is building the automated harness the group runs, said the bottleneck is not finding bugs but routing them to the right maintainers. "The hardest part is coordinating to get things to the right people," Hamilton, CEO of Anchorwatch, a Bitcoin self-custody insurance company, wrote on X. "While it is powerful, having found critical issues, I would view this as only version one."
The harness, which has grown to 171,599 lines of code, is designed to identify and test critical Bitcoin software libraries, reproduce vulnerabilities and package proven data into reports for engineers. Hamilton said the team intends to open-source the harness so Bitcoin companies can run it against their closed-source code.
The volume of findings is creating its own problems. Calle acknowledged "there's a lot of chaos right now in the ecosystem," apologizing to maintainers buried in reports and saying the group is still learning to sort out "the slop." The group publishes fast because maintainers can now verify findings almost for free using the same tools, and because "others who aren't on the red team will arrive at the same findings as we did."
The audit's impact is already rippling through the ecosystem. Boltz exchange announced it would pause operations to catch up with AI-driven hacking attempts, and the Coldcard incident has pushed some analysts to expect increased demand for regulated bitcoin exposure. Bitcoin traded at $64,741 as of 07:53 UTC, up 0.98 percent over 24 hours, as the market absorbed the security developments.
The broader implication is that AI has compressed the timeline between vulnerability discovery and exploitation. What took human researchers years to find can now be surfaced in hours at minimal cost, and the same tools that defenders use to audit code are available to attackers. The Bitcoin Red Team's findings — and the Coldcard exploit that preceded them — suggest the ecosystem's security posture will need to evolve as fast as the AI models probing it.
This article is for informational purposes only and does not constitute investment advice.