{"id":15204,"date":"2026-08-06T09:47:22","date_gmt":"2026-08-06T09:47:22","guid":{"rendered":"https:\/\/nile1.com\/en\/?p=15204"},"modified":"2026-08-06T09:47:28","modified_gmt":"2026-08-06T09:47:28","slug":"ai-agents-flag-5000-security-issues-across-390-bitcoin-projects-in-30-hour-sweep","status":"publish","type":"post","link":"https:\/\/nile1.com\/en\/2026\/08\/06\/ai-agents-flag-5000-security-issues-across-390-bitcoin-projects-in-30-hour-sweep\/","title":{"rendered":"AI Agents Flag 5,000 Security Issues Across 390 Bitcoin Projects in 30-Hour Sweep"},"content":{"rendered":"<p>A volunteer collective known as the Bitcoin Red Team has uncovered nearly 5,000 security findings across 390 Bitcoin-related software projects in a 30-hour period, relying heavily on artificial intelligence agents to scan open-source repositories.<\/p>\n<p>The audit logged 4,962 total findings at a rate of 166 per hour, according to an initial situation report released Wednesday by pseudonymous Cashu protocol creator calle. Among the issues identified, 85 were classified as critical severity and 635 as high severity\u2014representing 14.5% of the total dataset and averaging 1.85 serious vulnerabilities per audited repository.<\/p>\n<p>The operation involved 14 human contributors and three automated bots working around the clock. Automated intake pipelines accounted for 91% of the reported findings, though team members spent significant time guiding the AI agents. Letting individual contributors customize their own scanning methods and agent prompts &#8220;has proven to be the most effective strategy,&#8221; calle noted, as varied prompting techniques turned up distinct categories of code defects. Roughly 21% of all findings were dynamically verified using proof-of-concept code, while eight were retired as false positives.<\/p>\n<p>Flaws were disproportionately concentrated in privacy-focused protocols. Coinjoin and privacy tools recorded the highest share of serious findings, with 24% rated high or critical severity. Swaps and exchange infrastructure followed at 21%, while payment and merchant software logged 17%. Cryptographic libraries and software development kits generated the largest aggregate volume at 1,101 findings, though only 10% met the high-severity threshold.<\/p>\n<p>The automated sweep is putting new pressure on open-source maintainers. Only 19 projects\u2014less than 5% of those reviewed\u2014have received upstream disclosures so far. &#8220;We&#8217;re sincerely sorry if our reports added stress to your already stressful day,&#8221; calle wrote, arguing that rapid public reports are necessary because maintainers are best positioned to validate findings, particularly as AI tools make verification almost frictionless for developers and adversaries alike.<\/p>\n<p>The push highlights growing industry concern over AI-driven exploit discovery. In March 2021, a firmware build for <a href=\"https:\/\/nile1.com\/en\/2026\/08\/04\/coinkite-coldcard-firmware-bug-triggers-130-million-bitcoin-theft\/\" class=\"auto-internal-link\" title=\"Coinkite Coldcard Firmware Bug Triggers $130 Million Bitcoin Theft\">Coinkite<\/a>&#8216;s <a href=\"https:\/\/nile1.com\/en\/2026\/08\/04\/bitcoin-bridge-boltz-halts-swap-service-indefinitely-over-ai-assisted-attacks\/\" class=\"auto-internal-link\" title=\"Bitcoin Bridge Boltz Halts Swap Service Indefinitely Over AI-Assisted Attacks\">Coldcard<\/a> hardware wallet relied on a software fallback rather than a hardware random number generator, leaving private keys guessable and leading to user losses estimated at $130 million. Coinkite subsequently noted it was likely that &#8220;someone used AI to review previous versions of our firmware.&#8221;<\/p>\n<p><a href=\"https:\/\/nile1.com\/en\/2026\/08\/04\/bitcoin-bridge-boltz-halts-swap-service-indefinitely-over-ai-assisted-attacks\/\" class=\"auto-internal-link\" title=\"Bitcoin Bridge Boltz Halts Swap Service Indefinitely Over AI-Assisted Attacks\">Ledger<\/a> Chief Technology Officer <a href=\"https:\/\/nile1.com\/en\/2026\/08\/04\/bitcoin-bridge-boltz-halts-swap-service-indefinitely-over-ai-assisted-attacks\/\" class=\"auto-internal-link\" title=\"Bitcoin Bridge Boltz Halts Swap Service Indefinitely Over AI-Assisted Attacks\">Charles Guillemet<\/a> noted that malicious actors are already using AI models to search open-source codebases &#8220;at machine speed,&#8221; warning that &#8220;open source and reviewed are not the same thing.&#8221;<\/p>\n<div class=\"related-news-box\">\n<h3 class=\"related-news-title\">Read also:<\/h3>\n<ul class=\"related_news_list\">\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/08\/05\/meta-launches-muse-code-agent-with-restart-safe-architecture-for-long-horizon-engineering-tasks\/\">Meta Launches Muse Code Agent with Restart-Safe Architecture for Long-Horizon Engineering Tasks<\/a><\/li>\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/08\/05\/cloudflare-open-sources-ai-agent-operating-system-to-tackle-enterprise-security-risks\/\">Cloudflare Open Sources AI Agent Operating System to Tackle Enterprise Security Risks<\/a><\/li>\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/08\/05\/ninth-circuit-lifts-injunction-blocking-perplexity-ai-tools-on-amazon\/\">Ninth Circuit Lifts Injunction Blocking Perplexity AI Tools on Amazon<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A volunteer collective known as the Bitcoin Red Team has uncovered nearly 5,000 security findings across 390 Bitcoin-related software projects in a 30-hour period, relying heavily on artificial intelligence agents to scan open-source repositories. The audit logged 4,962 total findings at a rate of 166 per hour, according to an initial situation report released Wednesday &hellip;<\/p>\n","protected":false},"author":1,"featured_media":5107,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[7],"tags":[17809,17810,17811,17051,17812,14580,14672,8684,8162,2398],"class_list":["post-15204","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto","tag-bitcoin-red-team","tag-calle","tag-cashu","tag-charles-guillemet","tag-coinjoin","tag-coinkite","tag-coldcard","tag-ledger","tag-open-source","tag-privacy"],"_links":{"self":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/15204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/comments?post=15204"}],"version-history":[{"count":3,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/15204\/revisions"}],"predecessor-version":[{"id":15207,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/15204\/revisions\/15207"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media\/5107"}],"wp:attachment":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media?parent=15204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/categories?post=15204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/tags?post=15204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}