AI-Powered Bitcoin Audit Uncovers 85 Critical Bugs in Just Over a Day
- AI-assisted security testing uncovered thousands of potential issues across hundreds of Bitcoin projects in just 27.5 hours, revealing dozens of critical vulnerabilities.
- Developers say the biggest challenge is now verifying reports and directing them to the right maintainers rather than finding new bugs.
- The findings highlight how AI is accelerating both cybersecurity research and the techniques available to malicious actors.
A coordinated AI-assisted security review has uncovered 85 critical vulnerabilities across 390 Bitcoin projects after just over a day of analysis, highlighting both the capabilities of automated security research and the challenges it creates for developers.
The volunteer initiative involved 16 Bitcoin developers working continuously to examine wallets, cryptographic libraries and supporting infrastructure using AI-assisted review methods. After 27.5 hours, the team had submitted 4,962 findings, including 85 critical and 635 high-severity issues. The developer coordinating the effort described the situation as extremely serious while noting that human oversight remains necessary despite growing automation.
Many of the critical reports have already been verified by project maintainers and reproduced using proof-of-concept testing in local environments before being shared. However, the large volume of reports has created significant disruption, with maintainers facing an influx of findings that still require validation and prioritisation.
Related: Senate Races to Resolve Sticking Points as Crypto Market Structure Bill Faces Recess Deadline
AI Is Changing Security Workflows
The team said rapid disclosure allows maintainers to confirm issues using the same AI-powered tools, while reducing the likelihood that other researchers independently identify the same flaws first. According to one developer building the group’s automated systems, coordinating reports with the correct maintainers has become a greater challenge than discovering vulnerabilities.
The wider security landscape also reflects AI’s growing role in offensive research, with previous examples including a vulnerability found for under US$50 (AU$71) and an attempted criminal attack based on an AI-discovered flaw. Separately, Coldcard-related thefts have reached as much as US$114 million (AU$161.88 million) following exploitation of faulty firmware.
Related: a16z-Backed Proof of Play Shuts Down, Open-Sources Pirate Nation Assets