Brivv
Volunteer Bitcoin Developers Flag 85 Critical Bugs Using AI in Under a Day
CryptoNews3 min readAI-assisted

Volunteer Bitcoin Developers Flag 85 Critical Bugs Using AI in Under a Day

Sixteen Bitcoin developers used AI tools to uncover 4,962 security findings across 390 projects in a coordinated audit, including 85 critical and 635

August 6, 2026Source: coindesk.com

Sixteen Bitcoin developers have filed 4,962 security findings across 390 projects in a little over a day, including 85 critical and 635 high-severity issues, according to Calle, the pseudonymous developer behind the Cashu ecash protocol.

The findings stem from a coordinated audit in which developers pointed AI models at bitcoin wallets, cryptographic libraries and infrastructure. "Situation is extremely bad," Calle noted, adding: "We're ramping up. Much of our work is still manual (hand holding the AI) but our automated harnesses are getting better at the same time. So far, letting everyone use their own favorite review method has proven to be the most effective strategy."

Most critical reports have been quickly verified by project owners and reproduced with a working proof of concept in a local test environment before being sent, Calle said. He acknowledged the volume is creating its own problems, describing "a lot of chaos right now in the ecosystem" and apologizing to maintainers buried in reports as the group works to sort out what he called "the slop."

The team publishes fast because maintainers can now verify findings almost for free using the same tools, Calle said, and because "others who aren't on the red team will arrive at the same findings as we did."

Rob Hamilton, who is building the automated setup the group runs, said the bottleneck is not finding bugs but routing them to the right maintainers. "The hardest part is coordinating to get things to the right people," Hamilton wrote on X. "While it is powerful, having found critical issues, I would view this as only version one."

Attackers are using the same tools

  • The Coldcard sweeps, which began July 30 and have taken as much as $114 million from wallets whose seeds were generated by faulty firmware, stemmed from a bug dormant since 2021 that required no access to the physical device once the affected key space was known.
  • Anthropic said in April that one of its models, held back from public release and given only to vetted users, found a bug that had sat undiscovered in widely used software for 27 years, at a cost of less than $50. It found flaws in the encryption software that secures banking connections, exchange logins and the servers running most of the internet.
  • Google's threat intelligence team said in May it had caught a criminal group preparing an attack built on a flaw a model had found for them.

The audit shows how AI is reshaping security research for both defenders and attackers in the Bitcoin ecosystem.

Read the original report at CoinDesk

Related Articles