Volunteer Bitcoin Red Team Uses Frontier AI to Uncover Over a Dozen Critical Bugs

iconChainGPT
Share
AI summary iconSummary
A volunteer Bitcoin red team used frontier AI to scan 150 Bitcoin repositories and found over a dozen critical bugs. The Bitcoin news effort, led by AnchorWatch CEO Rob Hamilton, cost $20,000 and used models like Kimi K3, GPT Sol, and Claude Fable. OpenAI also helped with deeper scans. Developer Calle said the team found one critical exploit per hour, at a daily cost of $10,000. AI + crypto news shows similar tools are now used by attackers on Zcash, Coldcard, and Boltz.

Headline: Volunteer “Bitcoin red team” says frontier AI found a raft of critical bugs across core projects A volunteer security initiative building a Bitcoin “red team” says it used frontier AI models to scan roughly 150 Bitcoin repositories and uncovered more than a dozen vulnerabilities — highlighting a growing AI arms race in crypto security. AnchorWatch CEO Rob Hamilton, who helped organize the effort, told followers on X that the group has already spent about $20,000 on AI services while building the red-team platform. “We have been working around the clock, with ~$20,000 of spend up to this point across different services,” he wrote, adding that funding is secured and donations aren’t necessary. What they did and how - The red team used multiple high-end models to automate code review and vulnerability discovery: Kimi K3, OpenAI’s GPT Sol, Anthropic’s Claude Fable and Opus, and Z.ai’s GLM 5.2. - Hamilton said the team also worked with OpenAI to get a “Cyber Harness” running for heavier, more expensive scans — an approach he described as worth the cost for “load-bearing portions of the Bitcoin ecosystem.” - In total, the initiative scanned about 150 repositories and flagged more than a dozen vulnerabilities. The team has not disclosed which projects were affected or released technical details. Scale and cost Pseudonymous Bitcoin developer Calle, another member of the effort, said the initiative has built several AI-powered review systems that target wallets, cryptographic libraries, infrastructure, and other Bitcoin projects. “We're averaging on the order of one critical exploit per hour per person,” Calle wrote on X, and reported critical vulnerabilities to several projects within a 12-hour window. He also warned the exercise is expensive: “We're burning through $10,000 per day.” Why this matters The announcement underscores how AI is rapidly reshaping both defensive and offensive security work in crypto. AI-assisted audits can surface critical bugs faster and at scale — but the same tools are available to attackers. This trend has already shown real-world impact earlier this year: - Researchers using Anthropic’s Claude Opus 4.8 found a four-year-old Zcash flaw that could have allowed creation of counterfeit ZEC. - In August, Coldcard maker Coinkite said it believed attackers used AI to identify a Coldcard vulnerability. - Bitcoin bridge Boltz suspended swaps citing that attackers were using AI to find vulnerabilities faster than its team could patch them. The Bitcoin red team’s work is a reminder that as projects increasingly rely on software and cryptography, automated, AI-driven scrutiny is becoming a critical — if costly — layer of defense. The group’s findings and methods may push more teams to both adopt AI for audits and to harden disclosure and remediation processes, though the identities of vulnerable projects and the precise flaws remain confidential for now.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.