Bitcoin Red Team's AI Burn Rate: 16 Volunteers, 4,962 Bugs, $10K a Day 🎯
Back to feed

Bitcoin Red Team's AI Burn Rate: 16 Volunteers, 4,962 Bugs, $10K a Day 🎯

A volunteer security group called the Bitcoin Red Team has filed 4,962 potential vulnerabilities across 390 open-source Bitcoin projects in roughly 30 hours of AI-assisted scanning, describing the effort as a "large-scale ecosystem audit." Pseudonymous developer calle, who created the Cashu ecash protocol, published the campaign's first situation report on Wednesday, listing 85 critical-severity findings and 635 high-severity findings, together 14.5% of the corpus and an average of 1.85 serious issues per project, filed at a pace of 166 findings per hour. The team has grown to 16 globally distributed contributors working 24/7, with 14 humans and three automated agents logging effort in the report.

Much of the work remains manual, calle wrote, with contributors "hand holding the AI," though automated harnesses are improving and 91% of findings arrived through automated scan intake. Allowing reviewers to use their own preferred methods "has proven to be the most effective strategy," he said, because contributors prompt their agents differently and surface different bugs. About 21% of findings have been dynamically reproduced with proof-of-concept code, and eight have been retired as false positives.

The severity spread varies sharply by category. Privacy and coinjoin tools returned the highest proportion of high-or-critical findings at 24%, followed by swaps and exchanges at 21% and payments and merchant tools at 17%. Cryptographic libraries and SDKs produced the largest raw volume at 1,101 findings, but only 10% cleared the high bar. Only 19 projects, under 5% of those reviewed, have had findings disclosed upstream so far, and calle acknowledged the timing is difficult for maintainers. "We're sincerely sorry if our reports added stress to your already stressful day," he wrote, while arguing the findings should go out fast because project owners are best placed to validate them, validation is now nearly free with AI, and anyone else running the same tools will reach the same bugs.

The effort is being run by a small group that includes AnchorWatch CEO Rob Hamilton and calle, and is targeting wallets, cryptographic libraries, infrastructure and other Bitcoin projects. "We're averaging on the order of 1 critical exploit per hour per person," calle wrote on X, adding that the team has reported critical vulnerabilities to several projects in the last 12 hours. Hamilton separately said the group has spent about $20,000 so far across AI services, naming Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable and Opus models, and Z.ai's GLM 5.2 as tools in use, along with a more expensive OpenAI "Cyber Harness" scan for load-bearing portions of the $BTC ecosystem. "We're burning through $10,000 per day," calle wrote.

The campaign lands as Bitcoin's security assumptions face fresh scrutiny. Coinkite's Coldcard wallet lost users some $130 million after a March 2021 firmware build drew wallet seeds from a software fallback rather than the device's hardware random number generator, leaving private keys guessable, and the firm noted it was likely that "someone used AI to review previous versions of our firmware." Ledger CTO Charles Guillemet said the incident should serve as a warning for the cryptocurrency industry, and Boltz suspended its swap service after saying attackers were using AI to identify vulnerabilities faster than its team could patch them. Bitcoin payment processor BTCPay Server separately urged administrators to install version 2.4.2 and replace macaroons after warning of a critical vulnerability that could lead to stolen funds.

Mentioned Coins

$BTC
Share:
Publishercryptonewsroom.xyz
Published—
CategorySecurity

Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.

See our Terms of Service, Privacy Policy, and Editorial Policy.