
A series of recent security incidents involving Coldcard, Core Lightning and Liquid Network is showing how artificial intelligence is transforming vulnerability research across Bitcoin infrastructure.
The Bitcoin ecosystem has experienced several serious security breaches in recent months, raising concerns that AI could make it substantially cheaper and faster to uncover weaknesses hidden deep within financial software.
Coldcard wallets were recently targeted in an attack that drained about $114 million in bitcoin (BTC). Core Lightning developers also issued an emergency security notice after AI-generated reports uncovered legitimate vulnerabilities. More recently, white-hat hackers exploited a flaw in Blockstream’s Liquid Network, withdrawing approximately 4,000 BTC worth around $317 million. The group later returned 3,400 BTC after the vulnerability was patched.
Together, the incidents highlight a paradox in Bitcoin’s development. The network’s base layer has intentionally been designed with simplicity in mind to reduce security risks. Yet attempts to expand Bitcoin’s capabilities and improve transaction speeds through smart contracts and off-chain scaling networks have created more complicated software, increasing the number of places where bugs can emerge.
AI is now making it possible to examine these increasingly complex systems at unprecedented scale. In August, 16 Bitcoin developers deployed AI models to analyze 390 Bitcoin projects, generating almost 5,000 potential security findings. Among them were 85 issues that were initially classified as critical.
“At some point we have to admit it. AI is finding bugs that no human can find,” Gregory said in a Telegram message.
Gregory, a Bitcoin application developer, previously worked at Merrill Lynch and JPMorgan before co-founding CommerceBlock and becoming its CEO. His work has included Bitcoin protocols such as MainStay and the statechain implementation used by Mercury Wallet and Mercury Layer.
Although Mercury Layer is no longer operational, its open-source code remains available on GitHub. Gregory argued that AI has changed the security implications of legacy financial software because dormant code can now be analyzed at extremely low cost.
“If a model can wake a bug in finance C from 2006, it can probably read a statechain repo that has not moved,” he said.
That raises the possibility that vulnerabilities could still be hiding in Mercury’s older code. Gregory pointed to areas including key-share deletion, client-side transfer verification, backup transactions and the shrinking locktime mechanism as examples of code that could warrant renewed scrutiny.
“That is the new paradigm,” Gregory said. “Unused code stopped being unused the moment the cost of reading it dropped to zero.”





