AI Bitcoin Security Sweep Uncovers Thousands of Potential Flaws
A volunteer team of Bitcoin developers and security researchers has uncovered thousands of potential software vulnerabilities after launching an AI-assisted review of open-source Bitcoin projects following the recent Coldcard hardware wallet exploit, which resulted in losses of more than $100 million.
Known as Bitcoin Red Team, the initiative has reviewed more than 390 open-source repositories covering Bitcoin wallets, cryptographic libraries, infrastructure software and other core projects.
The campaign has so far produced 4,962 security findings, including 85 classified as critical and 635 rated as high severity.
The effort is led by Bitcoin developer Calle, creator of the Android version of Bitchat, and AnchorWatch CEO Rob Hamilton, alongside a globally distributed group of 16 volunteers.
The team has spent more than $40,000 on AI computing, with funding provided by OpenSats, a non-profit organisation that supports open-source Bitcoin development.
How AI Is Speeding Up Bitcoin Security Reviews
Rather than relying only on traditional manual audits, the team combines AI models with human verification to examine large amounts of code in a short period of time.
The review uses frontier AI models including Kimi K3, GPT Sol, Fable, Opus and GLM5.2.
The project initially depended heavily on Chinese open-source AI models before expanding to include OpenAI and Anthropic models as access became available.
According to Calle, the campaign has been progressing at an unusually fast pace.
"27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We're at 2.31 h+c findings per person per hour."
In another update, Calle said the group was "averaging on the order of 1 critical exploit per hour per person" and described the overall security situation as "extremely bad."
Not Every Finding Is A Confirmed Vulnerability
Although the number of reported issues is large, the team cautioned that the findings should not all be treated as confirmed exploitable vulnerabilities.
Around 21.4% of the reported issues have already been successfully reproduced, meaning those findings have been independently verified.
The remaining reports still require further investigation, as AI-assisted security reviews can generate false positives, duplicate reports or issues that may not be exploitable in real-world conditions.
Critical vulnerabilities are already being disclosed privately to affected open-source projects through a responsible disclosure process before any public release.
Open-Source Security Tools Planned For Wider Use
Alongside identifying vulnerabilities, Bitcoin Red Team plans to release its custom AI security harness as open-source software.
The framework is designed to identify important software libraries, reproduce vulnerabilities, package supporting evidence into reports and help developers coordinate responsible disclosures.
The team said the security harness could also allow Bitcoin companies to test their own closed-source software, extending the same review process beyond public repositories.
Hamilton said AI remains a tool rather than a replacement for experienced engineers, noting that engineers "...might otherwise 'smell out something is wrong,' but might be missing niche context."
The campaign continues to expand as contributors review more Bitcoin software while seeking additional computing resources and AI access to support the ongoing security effort.