Bitcoin Red Team Reports AI-Assisted Vulnerability Findings

A volunteer Bitcoin security initiative reported AI-assisted reviews of 390 Bitcoin-related projects during its first 29.8 hours, identifying 4,962 potential issues. Crypto.news reports that 720 findings were classified as high or critical severity, while ZeroHedge says 21.4% had been reproduced through verification. The group did not identify affected projects or disclose vulnerability details.
A volunteer initiative calling itself the Bitcoin Red Team reported that AI-assisted reviews of Bitcoin software identified 4,962 potential security issues across 390 projects during its first 29.8 hours of activity. According to Crypto.news and ZeroHedge, the group classified 720 findings as high or critical severity, and said 21.4% of findings had been reproduced through verification.
The reported campaign covers Bitcoin wallets, cryptographic libraries, infrastructure software, and other open-source projects. Bitcoin developer Calle wrote on X that the group had built multiple review harnesses and was averaging "We're averaging on the order of 1 critical exploit per hour per person," according to the two outlets. Calle also wrote that critical vulnerabilities had been reported to several projects.
AnchorWatch CEO Rob Hamilton said on X that the initiative had spent about $20,000 on AI services and had secured funding, ZeroHedge reports. Hamilton described the platform as using AI tooling to identify vulnerabilities and generate supporting documentation. The reporting does not provide a complete technical description of the models, prompts, harnesses, or verification workflow used.
Findings remain preliminary
The published figures are self-reported by the initiative and include potential issues rather than a public list of confirmed vulnerabilities. The distinction matters: automated code review can generate plausible but non-exploitable findings, especially in cryptographic and systems code where threat models, implementation details, and deployment context determine severity.
Crypto.news reports that the effort followed attacks involving vulnerable Coldcard hardware-wallet firmware. Neither source identifies the projects with reported critical vulnerabilities, and the group did not disclose exploit details. That limited disclosure is consistent with coordinated vulnerability reporting, but it prevents independent assessment of the stated severity counts.
For maintainers and security engineers, the report adds to evidence that AI-assisted auditing is being applied to large, interdependent open-source codebases. In comparable security-review efforts, reproducibility, manual triage, exploitability analysis, and responsible disclosure remain the controls that separate an automated finding queue from a verified vulnerability program.
Key Points
- 1The volunteer group reported 4,962 potential issues across 390 Bitcoin projects, but only 21.4% had been reproduced through verification.
- 2AI-assisted review can expand audit coverage across wallets and cryptographic libraries, while manual validation remains necessary to establish exploitability and severity.
- 3Undisclosed affected projects and exploit details limit independent evaluation, reflecting the tradeoff between coordinated disclosure and public transparency.
Scoring Rationale
The reported volume of AI-assisted findings is notable for engineers maintaining cryptocurrency and other security-sensitive open-source software. However, the figures are self-reported, most findings are not publicly documented, and the available reporting does not permit independent validation of the claimed critical vulnerabilities.
Sources
Public references used for this report.
Practice with real FinTech & Trading data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all FinTech & Trading problems

