Bitcoin developers flag 85 critical bugs in an "extremely bad" situation
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Sixteen Bitcoin developers employed AI tools to conduct a 24-hour security audit across 390 Bitcoin projects, uncovering 4,962 vulnerabilities. Among these, 85 critical and 635 high-severity bugs were flagged. Calle, a developer behind the Cashu ecash protocol, described the situation as "extremely bad," with the volume of findings overwhelming project maintainers. The group continues refining their AI-assisted review methods and coordinates closely with maintainers to verify and reproduce critical bugs.
Why it matters
The audit illustrates how AI is rapidly transforming security research by uncovering numerous vulnerabilities at a previously unseen scale and speed. This transformation affects both defenders in identifying weaknesses and attackers who now have access to similar tools. The flood of reports has created operational challenges for maintainers trying to respond quickly, highlighting the evolving dynamics of security in the Bitcoin ecosystem.
Key context
This audit occurs amid recent attacks exploiting long-dormant bugs, such as the Coldcard sweeps starting July 30, which reportedly led to losses of up to $114 million by exploiting firmware-generated seeds. The ability of AI to detect these vulnerabilities swiftly points to growing security risks. Furthermore, AI's role in uncovering vulnerabilities has been acknowledged by entities like Anthropic and Google, both of which have observed AI models discovering longstanding bugs and aiding threat actors.
Key numbers and entities
Key figures include 16 Bitcoin developers conducting the audit, 85 critical bugs, 635 high-severity bugs, and 4,962 total vulnerabilities found across 390 projects. Calle, the pseudonymous developer behind Cashu, and Rob Hamilton, responsible for the automation setup, are central individuals cited. The Coldcard attack involved losses of up to $114 million. No additional named organizations or figures are specified beyond these.
What remains unclear
The source signals ongoing challenges in effectively routing and managing the overwhelming number of bug reports but does not provide specific details on how these challenges will be resolved. It also remains unclear how the broader ecosystem will adapt to the increasing speed and scale of AI-driven vulnerability discovery beyond the initial audit phase.