Bitcoin Red Team's AI-Assisted Security Sprint Uncovers 6,700 Issues in 55 Hours
A recent AI-assisted security campaign, Bitcoin Red Team, has reported finding over 6,700 issues in just 55 hours while scanning 425 projects. The campaign, which utilized models like GPT Sol and GLM 5.2 to aid in the review process, labeled 1,029 of these findings as high or critical.
While the sheer volume of discoveries is impressive, the actual number of real security vulnerabilities remains unknown due to a lack of transparency in the campaign's reporting. The team behind Bitcoin Red Team reported that only 24 participants had confirmed the validity of their findings, with three of those being bots.
Rob Hamilton, one of the key figures involved in the project, noted that human subject-matter experts played a crucial role in shaping prompts and interpreting output from the AI models. However, he also acknowledged that the division of labor between humans and AI can create bottlenecks in the review process.
The campaign's findings have sparked debate about the efficacy and transparency of such large-scale security reviews. Critics argue that without clear definitions and denominators for the severity counts, it is difficult to determine how many alerts became confirmed vulnerabilities or led to patches.