Crypto

AI Agents Flag 5,000 Security Issues Across 390 Bitcoin Projects in 30-Hour Sweep

Automated scans reveal hundreds of critical vulnerabilities across open-source Bitcoin repositories as AI security tools accelerate.

A volunteer collective known as the Bitcoin Red Team has uncovered nearly 5,000 security findings across 390 Bitcoin-related software projects in a 30-hour period, relying heavily on artificial intelligence agents to scan open-source repositories.

The audit logged 4,962 total findings at a rate of 166 per hour, according to an initial situation report released Wednesday by pseudonymous Cashu protocol creator calle. Among the issues identified, 85 were classified as critical severity and 635 as high severity—representing 14.5% of the total dataset and averaging 1.85 serious vulnerabilities per audited repository.

The operation involved 14 human contributors and three automated bots working around the clock. Automated intake pipelines accounted for 91% of the reported findings, though team members spent significant time guiding the AI agents. Letting individual contributors customize their own scanning methods and agent prompts “has proven to be the most effective strategy,” calle noted, as varied prompting techniques turned up distinct categories of code defects. Roughly 21% of all findings were dynamically verified using proof-of-concept code, while eight were retired as false positives.

Flaws were disproportionately concentrated in privacy-focused protocols. Coinjoin and privacy tools recorded the highest share of serious findings, with 24% rated high or critical severity. Swaps and exchange infrastructure followed at 21%, while payment and merchant software logged 17%. Cryptographic libraries and software development kits generated the largest aggregate volume at 1,101 findings, though only 10% met the high-severity threshold.

The automated sweep is putting new pressure on open-source maintainers. Only 19 projects—less than 5% of those reviewed—have received upstream disclosures so far. “We’re sincerely sorry if our reports added stress to your already stressful day,” calle wrote, arguing that rapid public reports are necessary because maintainers are best positioned to validate findings, particularly as AI tools make verification almost frictionless for developers and adversaries alike.

The push highlights growing industry concern over AI-driven exploit discovery. In March 2021, a firmware build for Coinkite‘s Coldcard hardware wallet relied on a software fallback rather than a hardware random number generator, leaving private keys guessable and leading to user losses estimated at $130 million. Coinkite subsequently noted it was likely that “someone used AI to review previous versions of our firmware.”

Ledger Chief Technology Officer Charles Guillemet noted that malicious actors are already using AI models to search open-source codebases “at machine speed,” warning that “open source and reviewed are not the same thing.”

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button