AI-Powered Security Campaign Uncovers Thousands of Bitcoin Code Vulnerabilities
Bitcoin contributor Rob Hamilton fixed a wallet crash bug in Bitcoin Core using AI tools, revealing both the promise and limitations of AI-powered security research. The fix was part of Hamilton's 'Bitcoin Red Team' initiative, which uses AI to systematically audit Bitcoin-related open-source code. In their first major push, the group of 17 volunteers documented over 4,962 potential issues in just 30 hours.
Of those findings, 85 were classified as critical and 635 as high-severity. However, Hamilton acknowledged that finding bugs is only half the battle - getting maintainers to review, triage, and patch them is a significant challenge. The group's efforts were hindered when OpenAI blocked them from using its tools, but they pivoted to alternative AI systems.
The project has already surfaced thousands of potential issues, including dozens classified as critical. Hamilton had been experimenting with AI-assisted code analysis on Bitcoin Core as early as May, and the catalyst for the coordinated campaign was a Coldcard hardware wallet vulnerability in July that led to the theft of over 1,000 BTC.
Hamilton's effort is part of a broader initiative to improve the security of open-source software. The 'Bitcoin Red Team' aims to use AI to systematically audit Bitcoin-related code and identify potential vulnerabilities before they can be exploited by hackers.