A volunteer group calling itself the Bitcoin Red Team has completed a rapid, AI-assisted sweep of Bitcoin ecosystem codebases, filing 4,962 security findings across 390 projects in roughly 30 hours. Pseudonymous developer calle — creator of the Cashu ecash protocol — published the team’s first situation report Wednesday. The results are stark: 85 findings labeled critical and 635 high severity, together accounting for 14.5% of the total. That works out to an average of 1.85 serious issues per project and roughly 166 findings reported per hour. How they did it - The effort blends human review and AI tooling. Calle says the group has grown to 16 people working 24/7; the report logs 17 contributors in total (14 human, 3 automated). - About 91% of findings were ingested through automated scan pipelines, though calle emphasizes much of the work remains “hand‑holding the AI” while automated harnesses improve. Allowing contributors to use their own prompting and agent setups has reportedly surfaced different classes of bugs. - Approximately 21% of findings have been dynamically reproduced with proof‑of‑concept (PoC) code. Eight reported issues have been retired as false positives. Where the risks concentrate - The proportion of high-or-critical findings varies by category. Privacy and CoinJoin tools showed the highest rate (24%), followed by swaps and exchanges (21%), and payments/merchant tools (17%). - Cryptographic libraries and SDKs generated the largest raw volume of findings (1,101), but only about 10% of those were high or critical. Disclosure and community impact - So far, only 19 projects — under 5% of those scanned — have had findings disclosed upstream. Calle acknowledged the added pressure on already stretched maintainers and apologized for any stress, while arguing rapid reporting is necessary: project owners are best placed to validate issues, AI makes validation cheaper and faster, and attackers running the same tools will uncover the same bugs if defenders don’t act. Broader context: AI speeds up both attack and defense The campaign arrives amid renewed questions about Bitcoin software security in an era of AI-assisted code review. The report points to past high‑profile failures such as Coinkite’s Coldcard incident: a March 2021 firmware build used a software fallback for entropy that made private keys guessable and is estimated to have cost users roughly $130 million. In its post‑mortem, Coinkite suggested “someone used AI to review previous versions of our firmware” to find the flaw. Ledger CTO Charles Guillemet has similarly warned that AI lets adversaries identify vulnerabilities “at machine speed,” and that “open source and reviewed are not the same thing.” The Coldcard flaw reportedly existed in public code for more than five years before being discovered via AI-driven analysis — a reminder that attackers now have tools that can outpace traditional review cycles. Takeaway The Bitcoin Red Team’s fast, AI‑powered audit highlights two uncomfortable realities: many widely used Bitcoin projects still contain high‑severity bugs, and AI has dramatically compressed the time needed to find them. The incident underscores the urgency for maintainers and the broader ecosystem to adopt faster, continuous security processes and coordinated disclosure practices to keep pace with AI‑enabled adversaries.
AI-Powered Bitcoin Red Team Discovers 4,962 Security Issues in 30 Hours
ChainGPTShare
A Bitcoin Red Team using AI tools uncovered 4,962 security issues in 30 hours across 390 projects, including 85 critical and 635 high-severity findings. The AI + crypto news highlights that 91% of the issues came from automated scans, with 21% verified via proof-of-concept code. Privacy tools and CoinJoin had the most severe security breach risks at 24%. The report calls for faster security processes to match AI-driven threats.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.