A series of security incidents involving Coldcard, Lightning and Liquid is highlighting how artificial intelligence is reshaping the economics of vulnerability discovery across Bitcoin infrastructure.
Bitcoin-related infrastructure has faced several significant security events in recent months, fueling concerns that AI could make it far less expensive to identify deeply embedded flaws in financial software.
Attackers recently stole roughly $114 million worth of bitcoin (BTC) from Coldcard wallets, while Core Lightning developers issued an emergency warning after AI-assisted security reports uncovered legitimate vulnerabilities. More recently, white-hat hackers exploited a weakness in Blockstream’s Liquid Network, withdrawing about 4,000 BTC worth roughly $317 million. They later returned 3,400 BTC after the flaw was fixed.
These incidents expose a paradox at the heart of Bitcoin’s development. The Bitcoin base layer is deliberately kept simple to reduce potential risks, but efforts to add greater functionality and faster transactions through smart contracts and off-chain scaling solutions have resulted in increasingly complex codebases that can contain more vulnerabilities.
At the same time, AI is being deployed to search for security weaknesses on a much larger scale. In August, 16 Bitcoin developers used AI models to examine 390 Bitcoin-related projects, generating nearly 5,000 findings, including 85 vulnerabilities that were initially classified as critical.
“At some point we have to admit it. AI is finding bugs that no human can find,” Gregory said in a Telegram message.
Gregory, a Bitcoin application developer, previously held positions at Merrill Lynch and JPMorgan. He later co-founded CommerceBlock and served as its CEO, contributing to Bitcoin projects such as MainStay and the statechain technology used by Mercury Wallet and Mercury Layer.
Although Mercury Layer has since been discontinued, its open-source code remains available on GitHub. Gregory argued that AI fundamentally changes the security implications of leaving older financial software accessible.
“If a model can wake a bug in finance C from 2006, it can probably read a statechain repo that has not moved,” he said.
He also raised the possibility that undiscovered vulnerabilities could still exist in Mercury’s legacy code, including areas involving key-share deletion, client-side transfer validation, backup transactions and its shrinking locktime mechanism.
“That is the new paradigm,” Gregory said. “Unused code stopped being unused the moment the cost of reading it dropped to zero.”

More Stories
Bitcoin’s Rally Could Extend as Volatility Shorts Unwind, Two Prime CEO Says
Bitcoin Falls to $78,800 as BNB and DeFi Tokens Defy Market Weakness
Hunter Biden’s LAPTOP Memecoin Plan Sparks Instant Crypto Backlash