
A volunteer security group using AI models to analyze Bitcoin codebases says it is uncovering about one critical vulnerability every hour for each contributor, with daily computing expenses reaching around $10,000. The team has identified 85 critical bugs across 390 Bitcoin-related projects in just over a day.
The coordinated review effort, involving 16 Bitcoin developers, has produced 4,962 security findings, including 85 critical flaws and 635 high-risk vulnerabilities, according to Calle, the pseudonymous developer behind the Cashu ecash protocol.
The audit uses AI tools to examine Bitcoin wallets, cryptographic libraries, and infrastructure components for potential weaknesses. Calle described the current situation as “extremely bad” and said the team is increasing its efforts to expand coverage.
Although much of the process still requires developers to manually guide and verify AI results, the group’s automated systems are improving. Calle said allowing researchers to use their own preferred review approaches has been one of the most effective strategies so far.
Many of the critical vulnerabilities have already been confirmed by project maintainers, who are recreating the issues through proof-of-concept tests in local environments before fixes are developed. However, the flood of reports has also created new challenges for developers responsible for reviewing them.
Calle acknowledged that the ecosystem is experiencing significant disruption, with maintainers overwhelmed by incoming reports. He said the team is still working on improving its ability to separate valuable discoveries from inaccurate or low-quality findings.
The group is releasing findings quickly because maintainers can now validate reports at very low costs using similar AI tools. Calle also noted that vulnerabilities uncovered by the team could eventually be discovered by other researchers or attackers.
Rob Hamilton, who is developing the automated framework powering the project, said the biggest challenge is no longer identifying bugs but ensuring they reach the correct maintainers. He described the current system as an early version that still requires better coordination.
The AI-driven audit arrives as Bitcoin’s ecosystem continues dealing with the impact of previously hidden security flaws. The Coldcard wallet exploit, which began on July 30, resulted in losses of up to $114 million and was linked to a firmware vulnerability that had existed since 2021. Attackers were able to exploit the weakened key generation process without requiring physical access to affected devices.
Security researchers have also warned that AI-powered vulnerability discovery is becoming available to malicious actors. Anthropic revealed in April that one of its restricted AI models discovered a decades-old software flaw for less than $50. The vulnerability affected encryption systems widely used for banking services, exchange logins, and internet infrastructure.
Separately, Google’s threat intelligence team reported that it had disrupted a criminal campaign based on a vulnerability identified with help from an AI model.
The developments highlight a growing cybersecurity challenge: AI is becoming a powerful tool for both protecting digital systems and uncovering weaknesses that attackers can exploit.






