Key facts
- A coordinated security audit by 16 Bitcoin developers identified 85 critical and 635 high-severity bugs across 390 projects.
A volunteer group of 16 Bitcoin developers, dubbed the Bitcoin Red Team, has identified 85 critical and 635 high-severity bugs across 390 projects using AI tools. The findings are overwhelming project maintainers, highlighting the growing capability of AI in discovering software vulnerabilities.

The widespread discovery of critical bugs using AI underscores the evolving landscape of cybersecurity in the crypto space, where both developers and malicious actors can leverage advanced tools to find vulnerabilities at an unprecedented speed.
A volunteer group of 16 Bitcoin developers, operating as the Bitcoin Red Team, has conducted a large-scale security audit across 390 Bitcoin projects using AI agents. In approximately 30 hours, the team filed 4,962 security findings, including 85 critical and 635 high-severity bugs. This rapid discovery rate is overwhelming project maintainers, who are now tasked with validating and addressing the vulnerabilities.
Calle, the pseudonymous developer behind the Bitcoin ecash protocol Cashu and coordinator of the audit, stated that the findings are being disclosed quickly because project owners can validate them using similar AI tools, making the process nearly free. He acknowledged that the influx of reports is adding stress to maintainers' workloads.
The audit highlights the growing power of AI in identifying software flaws, a capability that can be leveraged by both defenders and attackers. This comes in the wake of incidents like the Coldcard wallet vulnerability, where a flaw in public code remained undiscovered for years until an adversary reportedly used AI to find it, leading to significant user losses.