A volunteer team of Bitcoin developers has flagged 85 critical vulnerabilities across 390 Bitcoin-related projects during a coordinated AI-assisted security audit, according to CoinDesk. The group, made up of 16 developers, filed 4,962 findings in a little over 24 hours, including 635 high-severity issues, after directing AI models at wallets, cryptographic libraries and infrastructure.
The development matters because Bitcoin’s software ecosystem relies on many independent projects, and maintainers are now being hit with a volume of bug reports that is difficult to process. Calle, the pseudonymous developer behind the Cashu ecash protocol, said many critical reports had been quickly verified by project owners, but also described significant disorder as teams work through the findings.
The audit also highlights a changing security landscape for crypto. AI tools are helping developers identify bugs faster, but the same capability can also be used by attackers. CoinDesk noted that the group is publishing findings quickly because maintainers can use similar tools to verify them and because others may independently discover the same weaknesses.
Coordination appears to be one of the main challenges. Rob Hamilton, who is building the automated setup used by the group, said the bottleneck is not finding bugs but getting reports to the correct maintainers. He described the current system as an early version despite its ability to uncover critical issues.
The findings arrive after another security incident involving Coldcard-related wallet sweeps that began July 30. CoinDesk reported those sweeps took as much as $114 million from wallets whose seeds were generated by faulty firmware, underscoring the risk when dormant flaws are discovered and exploited before they are fixed.