Bitcoin Red Team's AI-Powered Security Audit Unleashes Floodgate of Vulnerabilities
A recent vulnerability in Coldcard hardware wallets exploited to over $100 million has spurred the Bitcoin community into action. The Bitcoin Red Team, a group of software engineers and security experts, has launched an AI-driven security audit of open-source Bitcoin software.
Led by Calle and Rob Hamilton, the team has spent over $40,000 in AI tokens to scan more than 390 Open Source repositories across Bitcoin. In just 27.5 hours, they've identified 4,962 vulnerabilities, including 85 critical and 635 high-severity issues.
The Red Team is using cutting-edge AI models like Kimi K3, GPT Sol, Fable, Opus, and GLM5.2 to identify potential security threats. Their custom-built harness has already identified critical vulnerabilities in various Bitcoin software libraries and high-load-bearing code.
Hamilton and Calle are actively reaching out to open-source projects with critical vulnerabilities, leading to a sense of dread among engineers in the industry. The Red Team's efforts aim to strengthen Bitcoin's cybersecurity and prevent future catastrophic hacks like the one that affected Coldcard users.