AI-Powered Security Campaign Uncovers 6,700 Bitcoin Project Flaws, But Lacks Transparency
A recent AI-assisted security campaign targeting Bitcoin projects, known as Bitcoin Red Team, reported 6,700 findings across 425 projects within its first 55 hours. Of those, 1,029 were labeled as high or critical.
However, the campaign's organizers failed to provide details on how many of these findings turned out to be actual security vulnerabilities. The missing numbers are crucial in assessing the campaign's effectiveness and impact on the projects' security.
The lack of transparency is due to the absence of audit-ready definitions for severity labels, case-level outcomes, and aggregate false-positive rates. This makes it difficult to determine how many alerts were confirmed as vulnerabilities, how many maintainers downgraded or rejected them, and how many resulted in patches.
The campaign's lead developer, Rob Hamilton, attributed the speed of the findings to a human-AI review system, where models did broad searching while specialists shaped prompts, read the output, and judged which reports were ready for disclosure. The effort demonstrated that an AI system can flood a review pipeline at the scale of an entire project set quickly.