Bitcoin Projects Face Widespread Vulnerabilities in Large-Scale Security Audit
A large-scale security audit of Bitcoin projects has uncovered 4,962 findings across 390 projects in just 30 hours. The effort, led by a volunteer group called the Bitcoin Red Team, used AI agents to scan code and identify vulnerabilities.
The team's report logs 17 contributors, 14 human and three automated, who worked around the clock to file the findings. Around 21% of the issues have been dynamically reproduced with proof-of-concept code.
Calle, a pseudonymous developer and creator of the Bitcoin ecash protocol Cashu, published the campaign's first situation report on Wednesday. He noted that much of the work is still manual, with human contributors 'hand holding the AI,' but automated harnesses are improving.
The severity spread varies sharply by category, with privacy and coinjoin tools returning the highest proportion of high-or-critical findings at 24%. Cryptographic libraries and SDKs produced the largest raw volume at 1,101 findings, but only 10% cleared the high bar.