All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Bitcoin developers flag 85 critical bugs using AI

Created at 6 Aug · 8:06 AM1 source↑ Market-relevant
IN SHORT

A team of 16 Bitcoin developers utilized AI tools to identify 4,962 security vulnerabilities, including 85 critical and 635 high-severity bugs, across 390 projects in just over a day. The sheer volume of findings is overwhelming project maintainers, highlighting AI's transformative impact on security research.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

85critical bugs flagged
635high-severity bugs flagged
4,962total security vulnerabilities found
390projects audited
16developers involved in the audit
24 hourstimeframe for initial findings
$114 millionlost from wallets due to faulty firmware bug
27 yearsflaw undiscovered in widely used software
$50cost to find a 27-year-old software flaw

Who's Involved

Calle
Pseudonymous developer behind the Cashu ecash protocol and coordinator of the audit
Rob Hamilton
Developer building the automated setup for the bug-finding group
Anthropic
AI company whose model found a long-standing software flaw
Google
Threat intelligence team that caught a criminal group using AI-found flaws
Bitcoin developers flag 85 critical bugs using AI

↳ Why This Matters

The rapid discovery of critical bugs using AI tools, while beneficial for security research, highlights a growing arms race where attackers can leverage the same technology. This poses a significant risk to the security of cryptocurrency projects and the broader digital infrastructure.

Key facts

  • A coordinated security audit by 16 Bitcoin developers identified 85 critical and 635 high-severity bugs across 390 projects.
  • The developers used AI tools to find the vulnerabilities in just over a day.
  • Project maintainers are struggling to manage the high volume of verified critical bug reports.
  • The audit demonstrates AI's increasing capability in discovering software flaws.
  • Attackers also have access to similar AI tools, posing a significant threat.
  • A previously undiscovered flaw in widely used software was identified by an AI model for a minimal cost.

A coordinated security audit involving 16 Bitcoin developers has identified a significant number of vulnerabilities, including 85 critical bugs, across 390 projects in just over a day. The developers utilized AI tools to scan wallets, cryptographic libraries, and infrastructure, leading to a deluge of findings that are currently overwhelming project maintainers.

Calle, the developer behind the Cashu ecash protocol, described the situation as "extremely bad," noting that while most critical reports are being quickly verified, the sheer volume is causing chaos within the ecosystem. The group is able to publish findings rapidly because maintainers can verify them using similar tools, and because "others who aren't on the red team will arrive at the same findings as we did."

Rob Hamilton, who is developing the automated setup for the audit, stated that the primary bottleneck is not finding bugs but coordinating their delivery to the correct maintainers. He characterized the current effort as "version one" of this process.

This audit comes at a time when the crypto ecosystem is still grappling with the fallout from security breaches. For instance, the Coldcard sweeps, which resulted in significant losses from wallets with faulty firmware, stemmed from a bug dormant since 2021. The accessibility of advanced AI tools to malicious actors is a growing concern, as demonstrated by Anthropic's discovery of a 27-year-old software flaw for less than $50, and Google's intelligence team catching a criminal group preparing an attack based on an AI-discovered vulnerability.

Frequently asked questions

A total of 85 critical bugs were flagged by the developers during the audit.

The developers utilized AI tools to scan Bitcoin wallets, cryptographic libraries, and infrastructure.

Yes, the article indicates that attackers have access to the same AI tools, posing a significant threat.

An AI model found a flaw that had been undiscovered for 27 years in widely used software for less than $50.

What Happens Next

01Project maintainers will continue to verify and address the reported critical bugs.
02The development team plans to improve their AI tools and coordination methods for future audits.
03The broader crypto community will likely increase its focus on AI-driven security vulnerabilities.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence
CME Headlines
  • Amendments to the Strike Price Listing Schedule for all Hourly Event Contract Swaps on Ether
    5 Aug · 7:15 PM

How It Developed

Sixteen Bitcoin developers used AI tools to audit 390 projects.
They identified 4,962 security vulnerabilities, including 85 critical and 635 high-severity bugs.
The volume of findings is overwhelming project maintainers.
The audit highlights AI's rapid transformation of security research.
A dormant bug in widely used software was found by an AI model for less than $50.
A criminal group was caught preparing an attack built on a flaw found by an AI model.

Sources

T1
Bitcoin developers flag 85 critical bugs in an "extremely bad" situationCoinDesk

Related Stories

Bitcoin Red Team Finds Nearly 5,000 Security Issues in Ecosystem Audit
6 Aug · 1:20 AM
Bitcoin holds above $64,000 amid SpaceX stock unlock watch
6 Aug · 5:06 AM
Bitcoin mempool transaction count spikes after Coldcard hack
5 Aug · 11:26 AM
Coldcard hack prompts self-custody security upgrades, says Swan CEO
5 Aug · 10:06 AM
Strategy Analysts Cut MSTR Price Targets Amid Bitcoin Sales
5 Aug · 10:51 AM