TLDRocket
Sign in

Volunteer “Bitcoin Red Team” uses AI to audit Bitcoin repositories and finds 85 critical flaws

coinalertnews.com

AI scanners found 85 critical bugs in Bitcoin code. The audit was so fast it’s already forcing exchanges and wallet teams to scramble.

Based on reporting by coinalertnews.com — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

A volunteer Bitcoin security team says it used AI to rip through open-source Bitcoin projects and turn up 85 critical vulnerabilities in just 27.5 hours. The group, Bitcoin Red Team, was led by developer Calle and AnchorWatch CEO Rob Hamilton, and it says the first sweep covered 390 repositories and 171,599 lines of code.

The pace is the part that should make Bitcoin people sit up. The team filed 4,962 findings in total, including 635 high-severity issues, with 16 researchers working around the clock. Calle’s read was blunt: the numbers suggest the situation is “extremely bad.”

This didn’t start as a neat research exercise. It was triggered by a critical random number generator flaw in Coldcard MK3+ hardware wallets, a bug that has already been tied to more than $100 million in confirmed Bitcoin losses and at least 15 attackers, according to Galaxy Research. OpenSats paid for more than $40,000 in AI compute, and the project leaned on models including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2.

There’s also a bigger story here about access. The team initially had trouble getting OpenAI and Anthropic access, so it leaned on Chinese open-source models at first, something observers flagged as a sign of uneven U.S. AI access. Hamilton later said OpenAI and Anthropic have since granted access, and the plan is to open-source the audit harness so Bitcoin companies can test closed-source codebases.

The immediate hit is already showing up. Boltz exchange has paused operations to deal with vulnerabilities the audit surfaced, which is exactly the kind of knock-on effect you’d expect when AI starts acting like an industrial-scale bug hunter. Maintainers now have the ugly part: reproduce the flaws, rank them, patch them, and hope the details don’t leak before the fixes land.

My take — AI-written commentary, not fact-checked reporting

This is what happens when crypto treats “code is law” like a warm blanket instead of a warning label. A volunteer team with AI found 85 critical bugs in a few hours; that’s not a victory lap, it’s a flashing red light. The industry loves to brag about decentralization right up until security work shows how much of it still runs on hope and a few exhausted humans.

Read more about this at: coinalertnews.com

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.