A volunteer group using AI models to scan Bitcoin codebases reports finding roughly one critical bug per person per hour, with compute costs nearing $10,000 per day. In just over 24 hours, the team identified 85 critical vulnerabilities across 390 Bitcoin-related projects.
The effort, led by 16 developers, has produced 4,962 total findings, including 85 critical and 635 high-severity issues, according to Calle, the pseudonymous creator of the Cashu ecash protocol.
The discoveries stem from a coordinated audit in which developers deployed AI tools to analyze Bitcoin wallets, cryptographic libraries, and supporting infrastructure.
Calle described the situation as “extremely bad,” noting that the team is rapidly scaling its efforts. While much of the process still involves manual oversight of AI outputs, automation is steadily improving. Allowing contributors to use their preferred review methods has also proven effective.
Most critical vulnerabilities have already been confirmed by project maintainers, who are reproducing them locally using proof-of-concept setups before taking action. However, the sheer volume of reports is creating its own challenges.
“There’s a lot of chaos right now in the ecosystem,” Calle said, apologizing to maintainers overwhelmed by incoming reports and acknowledging that the team is still refining how to filter low-quality findings.
The group is publishing results quickly, arguing that maintainers can now validate issues at minimal cost using similar AI tools. Calle also noted that others outside the team are likely to uncover the same vulnerabilities independently.
Rob Hamilton, who is building the automated system behind the audit, said the main bottleneck is no longer identifying bugs but ensuring they reach the right developers. “The hardest part is coordinating and getting findings to the right people,” he said, describing the current system as an early-stage version.
The audit comes at a time when the ecosystem is already dealing with the consequences of overlooked vulnerabilities. The Coldcard wallet exploit, which began on July 30 and has resulted in losses of up to $114 million, was traced to a firmware flaw dating back to 2021. Once attackers identified the weak key space, they were able to drain wallets without needing physical access to the devices.
Meanwhile, the same AI capabilities are increasingly accessible to attackers. In April, Anthropic revealed that one of its restricted-access models identified a long-hidden bug in widely used software for under $50. The flaw had gone unnoticed for 27 years and affected encryption systems used in banking, exchange logins, and much of the internet’s infrastructure.
In a separate case, Google’s threat intelligence team reported in May that it had intercepted a criminal group preparing an attack based on a vulnerability discovered with the help of an AI model.
Together, these developments highlight a growing reality: the tools used to secure systems are also being leveraged to exploit them, intensifying the race between defenders and attackers in the Bitcoin ecosystem.

More Stories
JPMorgan Warns Hyperliquid ETF Momentum Has Slowed as Rival Products Gain Ground
Sandisk and Western Digital’s 10% Drop Sparks Market Concerns Over Bitcoin’s Next Move
Bitcoin and Ether Gain Ground as Investors Return to Crypto’s Biggest Assets