Bitcoin Red Team Identifies Over 1,000 Critical Vulnerabilities Using AI
A grassroots security initiative called the Bitcoin Red Team conducted an audit sprint on roughly 390 open-source Bitcoin-related projects and identified over 1,000 critical vulnerabilities using AI. The effort was triggered by a major firmware vulnerability in Coldcard hardware wallets that led to estimated losses between $70 million and $114 million.
The team used open-weight AI models to accelerate the scanning process, averaging approximately 2.31 high or critical findings per person-hour over the 30-hour sprint. Only about 21.4% of the findings had been independently reproduced at the time of reporting.
The results were filed directly with project maintainers, creating a pipeline for responsible disclosure. The team plans to open-source the custom-built security harness designed specifically for this kind of rapid vulnerability discovery.