Key facts
- A coordinated security audit by 16 Bitcoin developers identified 85 critical and 635 high-severity bugs across 390 projects.
- The developers used AI tools to find the vulnerabilities in just over a day.
- Project maintainers are struggling to manage the high volume of verified critical bug reports.
- The audit demonstrates AI's increasing capability in discovering software flaws.
- Attackers also have access to similar AI tools, posing a significant threat.
- A previously undiscovered flaw in widely used software was identified by an AI model for a minimal cost.
A coordinated security audit involving 16 Bitcoin developers has identified a significant number of vulnerabilities, including 85 critical bugs, across 390 projects in just over a day. The developers utilized AI tools to scan wallets, cryptographic libraries, and infrastructure, leading to a deluge of findings that are currently overwhelming project maintainers.
Calle, the developer behind the Cashu ecash protocol, described the situation as "extremely bad," noting that while most critical reports are being quickly verified, the sheer volume is causing chaos within the ecosystem. The group is able to publish findings rapidly because maintainers can verify them using similar tools, and because "others who aren't on the red team will arrive at the same findings as we did."
Rob Hamilton, who is developing the automated setup for the audit, stated that the primary bottleneck is not finding bugs but coordinating their delivery to the correct maintainers. He characterized the current effort as "version one" of this process.
This audit comes at a time when the crypto ecosystem is still grappling with the fallout from security breaches. For instance, the Coldcard sweeps, which resulted in significant losses from wallets with faulty firmware, stemmed from a bug dormant since 2021. The accessibility of advanced AI tools to malicious actors is a growing concern, as demonstrated by Anthropic's discovery of a 27-year-old software flaw for less than $50, and Google's intelligence team catching a criminal group preparing an attack based on an AI-discovered vulnerability.
