AI Audit Finds 85 Critical Flaws Across 390 Bitcoin Open-Source Projects
The Bitcoin Red Team used frontier AI models to identify nearly 5,000 vulnerabilities in 27.5 hours following a massive Coldcard exploit.
A volunteer security group known as the Bitcoin Red Team has identified thousands of vulnerabilities across the Bitcoin ecosystem using an AI-accelerated auditing process. This blitz scan marks a significant escalation in the use of artificial intelligence to secure—and potentially threaten—open-source financial software.
Led by Calle and Rob Hamilton, the team scanned 390 open-source repositories in just 27.5 hours. The effort yielded 4,962 total findings, including 85 critical and 635 high-severity vulnerabilities. To achieve this scale, the group utilized a custom software harness that grew to 171,599 lines of code, leveraging frontier AI models such as Kimi K3, GPT Sol, Fable, Opus, and GLM5.2. The project was funded by the non-profit OpenSats, which provided more than $40,000 in AI tokens.
The Catalyst for AI Auditing
This proactive surge in security scanning was triggered by a catastrophic failure in Coldcard hardware wallets. A vulnerability in the devices' random number generation (RNG) led to the theft of over $100 million, proving that even highly trusted hardware can harbor devastating flaws. Because the Bitcoin ecosystem relies heavily on open-source software for self-custody, the Red Team sought to shift the security paradigm from slow, manual audits to high-speed, AI-augmented scanning to find holes before malicious actors do.
A Shift in Cybersecurity
The results demonstrate a fundamental shift in the cybersecurity landscape, where AI can now identify thousands of flaws in a fraction of the time required by human auditors. This speed underscores the fragility of the current open-source security model. The threat is already manifesting in the real world; Boltz exchange recently announced it would pause operations specifically to keep pace with AI-driven hacking attempts. As Rob Hamilton noted, the stakes are absolute, stating, "There is no Bitcoin without self-custody. This is non-negotiable."
The Future of Self-Custody
The emergence of "AI-driven hacking" suggests that developers must now adopt similar AI tools for defense to maintain the viability of self-custody. The industry is moving toward a state of perpetual, automated warfare between AI-powered attackers and defenders. Moving forward, the community will likely watch whether these 85 critical flaws are patched rapidly and if other major Bitcoin projects adopt the Red Team's harness to prevent similar systemic collapses.