A coordinated AI-assisted security audit has uncovered 85 critical vulnerabilities and 635 high-severity issues across 390 Bitcoin-related projects in just over 24 hours, highlighting growing concerns about the security of the Bitcoin ecosystem.
The initiative involved 16 Bitcoin developers who submitted a total of 4,962 findings after using AI models to analyze Bitcoin wallets, cryptographic libraries, and core infrastructure. The audit was organized by Calle, the pseudonymous developer behind the Cashu ecash protocol, who described the current security situation as "extremely bad."
According to Calle, most critical vulnerabilities have already been confirmed by project maintainers. Developers are reproducing the issues in local test environments with proof-of-concept exploits before sharing detailed reports. While AI significantly accelerates vulnerability discovery, the large number of findings has created challenges in coordinating disclosures and managing reports.
Calle said the team continues to improve its automated testing tools while still relying on manual review to validate AI-generated results. Allowing contributors to use their preferred security review methods has also helped uncover more legitimate vulnerabilities. He added that findings are disclosed quickly because maintainers can now verify reports using similar AI tools, reducing response time and limiting the risk of attackers discovering the same flaws first.
Rob Hamilton, who is helping build the group's automated auditing system, said the biggest challenge is no longer identifying vulnerabilities but ensuring they reach the correct project maintainers. He described the current effort as an early version of a much larger security initiative.
The audit comes shortly after the Coldcard wallet incident, where attackers reportedly exploited a firmware bug dating back to 2021, leading to the theft of as much as $114 million from affected wallets. The incident demonstrated how long-hidden software flaws can have devastating consequences once discovered.
The findings also reflect a broader cybersecurity trend. Earlier this year, Anthropic revealed that one of its advanced AI models identified a software vulnerability that had remained undetected for 27 years, while Google's Threat Intelligence Group disclosed it had disrupted a criminal operation attempting to weaponize an AI-discovered security flaw. Together, these developments underscore how AI is rapidly reshaping both cybersecurity defense and cyber threats.
Comment 0