AI Tool Discovers 5,000 Security Vulnerabilities in the Bitcoin Ecosystem

iconTechFlow
Share
AI summary iconSummary
Bitcoin news emerged as an AI tool uncovered 5,000 security vulnerabilities in the Bitcoin ecosystem. Volunteer developers used Kimi K3 to scan 390 projects in 24 hours, identifying 85 critical and 635 high-severity flaws. Most issues have been confirmed by the respective project teams. The audit followed a $100 million security breach involving the Coldcard hardware wallet. A 16-member team led by Calle is using AI to both secure and test the system, sparking debate over risk and protection within the Bitcoin space.

Article by: Forbes

Compiled by AididiaoJP, Foresight News

Bitcoin and cryptocurrency traders haven't yet recovered from a massive attack worth approximately $100 million, which briefly sparked panic over a new wave of price declines.

Since news of the attack on the hardware wallet Coldcard first emerged, Bitcoin's price has rebounded slightly but remains near recent lows. Traders are on edge, fearing another sharp downturn.

Against this backdrop, Bitcoin developers used AI tools to uncover nearly 5,000 security vulnerabilities across nearly 400 projects within just 24 hours. The situation was described directly as “extremely bad.”

A team of volunteer Bitcoin developers is conducting a large-scale, coordinated security audit. They have confirmed that the overall security of the ecosystem is "extremely bad."

Within 24 hours, they scanned approximately 390 Bitcoin-related projects and identified a total of 4,962 security vulnerabilities, including 85 critical-level and 635 high-severity vulnerabilities. The vast majority of these vulnerabilities have been verified by the project teams.

“We’ve grown to 16 people, globally distributed and on 24/7 shifts,” wrote Calle, the anonymous developer behind the Cashu ecash protocol, on X. “We’re conducting a large-scale ecosystem security audit of the Bitcoin codebase.”

The audit team uses Moonshot’s Kimi K3 model—an open-weight, Chinese-developed AI tool. Calle revealed that the team spends approximately $10,000 per day on computing power, covered by OpenSats.

"We've been working around the clock," said Rob Hamilton, CEO of Bitcoin insurance firm AnchorWatch and a member of the audit team, on X, noting that the team has identified several "critical issues."

The efficiency of this audit was astonishing. Developers reported that, on average, a critical vulnerability was discovered roughly every hour. AI is rapidly becoming an accelerator for both defense and offense—a trend already evident in the recent Coldcard incident.

Over the past year, Bitcoin's price has already declined significantly, leaving the market highly sensitive to further drops. The sudden emergence of hardware wallet security incidents has once again brought the question of whether self-custody is truly safe to the forefront.

Last week, the Coldcard Bitcoin hardware wallet was exploited, with nearly 2,000 bitcoins—valued at just over $100 million—withdrawn from over 5,200 addresses within a few days. The attackers exploited a key generation flaw that had existed for five years.

The Coldcard team has urgently called on users to transfer their funds and has repeatedly requested on social media that everyone help spread the word.

"Please treat this as an emergency," the Coldcard official account wrote. "Immediately migrate your funds. Upgrade your device, generate a new seed, and carefully transfer your funds according to the recommendations for your device model... the threat is ongoing."

A wallet address associated with the hacker still holds approximately $36 million in Bitcoin, the vast majority of which is believed to be stolen funds. Since the incident came to light, the address has received multiple incoming transfers, some of which included messages embedded via Bitcoin’s OP_RETURN feature.

Someone commented: “I launder BTC, complete KYC, and cash out. I take 10%.” This was interpreted as a solicitation for money laundering, attempting to turn hackers into clients. More comments were direct appeals requesting the return of stolen bitcoins.

On-chain analysts have pointed out that the vulnerability has been made public and is receiving intense attention, and cutting-edge large models are now accessible to nearly everyone, meaning multiple hacker teams may already be simultaneously researching how to expand their gains. "You're racing against time."

Another anonymous co-owner of bitcoin.org, Cobra, bluntly said he had a “very bad feeling” that AI may already be involved in the event that drained funds from Coldcard.

This AI-driven vulnerability scan, combined with the recent large-scale theft from Coldcard, is pushing the security issues of the Bitcoin ecosystem to a new tipping point. While developers use AI to accelerate vulnerability discovery, attackers may use the same tools to accelerate exploitation, compressing the window available for patching and migration.

Currently, the price of Bitcoin remains in a low-range consolidation, with traders awaiting the next potential move. This audit, which burns $10,000 in computing power daily, may just be the beginning of a broader security review.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.