Jameson Lopp Says AI-Assisted Flaw Discovery Outpaces Bitcoin Crypto Risk
The Bitcoin developer says attackers are more likely to exploit wallet and software weaknesses than break Bitcoin’s underlying cryptography.

Jameson Lopp, a Bitcoin (BTC) developer and Casa co-founder, said AI-assisted discovery of flaws in wallets and other software poses a more immediate security concern than the possibility of artificial intelligence breaking Bitcoin’s cryptography.
Lopp said concerns about AI breaking Bitcoin’s cryptography are receiving too much attention while attackers are already using AI to identify implementation weaknesses. Such flaws can expose funds without defeating the mathematical assumptions behind Bitcoin.
The debate involves the Elliptic Curve Digital Signature Algorithm, or ECDSA, used by Bitcoin and other blockchain systems. No active Bitcoin ECDSA key has been publicly shown to have been cracked using AI.
Software-vulnerability disclosures rose from 5,045 in January 2026 to 10,740 in August. Vulnerabilities exploited in the wild averaged 10.5 per month in 2025 and 18 per month from January through August 2026.
The figures provide context for Lopp’s focus on wallet software, firmware and other infrastructure. An error in one of those systems could allow attackers to compromise funds even if Bitcoin’s underlying cryptography remains secure.
Anthropic said its Claude Mythos Preview improved the best-known attack against the HAWK digital-signature scheme after 60 hours of work, reducing the scheme’s effective key strength by half. The company also described the system as capable of finding vulnerabilities and developing proof-of-concept exploits in tested software.
The HAWK result shows that AI can assist with specialized cryptanalysis, but it does not establish that Bitcoin’s ECDSA keys can currently be recovered. The issue is separate from the quantum-computing threat addressed in Ethereum’s preparations for AI-related cryptographic risks.
Lopp’s position is that developers and wallet operators should prioritize code review, testing and operational security before focusing on theoretical future attacks against Bitcoin’s cryptographic system.