Bitcoin Faces Urgent Risk After Developers Identify 85 Critical Vulnerabilities

A volunteer group using AI to audit Bitcoin code says it is discovering roughly one critical vulnerability per person per hour, with compute costs nearing $10,000 per day. In just over 24 hours, the team uncovered 85 critical bugs across 390 Bitcoin-related projects.

The coordinated audit, carried out by 16 developers, has generated 4,962 findings in total, including 85 critical and 635 high-severity issues, according to Calle, the pseudonymous developer behind the Cashu ecash protocol.

The effort relies on AI models scanning Bitcoin wallets, cryptographic libraries, and core infrastructure. Calle described the situation as “extremely bad,” noting that the team is scaling quickly. While human oversight is still required, automated tools are improving, and letting contributors use their preferred review methods has proven effective.

Most critical vulnerabilities have already been confirmed by project maintainers, who are reproducing them in local test environments before addressing them. Still, the volume of reports is creating significant pressure.

“There’s a lot of chaos right now in the ecosystem,” Calle said, acknowledging that maintainers are overwhelmed and that the team is still working to filter out low-quality findings.

The group is releasing results quickly, arguing that maintainers can now verify issues at minimal cost using similar tools, and that others are likely to discover the same flaws independently.

Rob Hamilton, who is building the automation framework behind the audit, said the main challenge is no longer finding bugs but directing them to the right teams. “Coordination is the hardest part,” he said, describing the system as still in its early stages.

The audit comes as the ecosystem is already grappling with the consequences of overlooked vulnerabilities. The Coldcard wallet exploit, which began on July 30, has led to losses of up to $114 million and was traced to a firmware flaw dating back to 2021. Once attackers identified the weak key space, they were able to drain wallets without needing physical access.

Meanwhile, similar AI tools are increasingly accessible to attackers. In April, Anthropic revealed that one of its restricted models uncovered a long-hidden bug in widely used software for under $50. The flaw had gone undetected for 27 years and impacted encryption systems used in banking, exchange logins, and core internet infrastructure.

In a separate case, Google’s threat intelligence team said in May it had disrupted a criminal group preparing an attack based on a vulnerability discovered using AI.

These developments highlight a growing reality: the same AI tools accelerating security research are also making it easier to exploit weaknesses, intensifying the race between defenders and attackers across the Bitcoin ecosystem.