AI-led audit flags 85 critical bugs across 390 Bitcoin-related projects

AI-led audit flags 85 critical bugs across 390 Bitcoin-related projects

N
News Editor
2026-08-07 11:17:54
An AI-assisted security review conducted by a 16-member group of Bitcoin developers has identified 85 critical vulnerabilities across 390 Bitcoin-related projects, according to Blockcast. The effort also logged 4,962 potential risks in total, including 635 high-risk issues, after examining Bitcoin wallets, cryptographic libraries, and other infrastructure. Calle, the pseudonymous developer behind the e-cash protocol Cashu who coordinated the effort, said the findings showed the situation was "very bad." Rob Hamilton, the developer who built the automated auditing system, said the main obstacle is no longer finding flaws but securely and accurately reporting sensitive vulnerability details to the right project maintainers. He described the current system as a "1.0 version" despite its ability to uncover serious defects. The report also pointed to the recent Coldcard hack as a reminder of how dangerous long-standing software flaws can be. The incident, which broke out on July 30, has led to $114 million in user assets being stolen. According to the report, the breach traced back to a firmware vulnerability that had existed since 2021, showing that even funds kept in cold wallets can remain exposed if the underlying software is flawed.

A 16-member team of Bitcoin developers used AI models to run a large-scale security audit and found 85 critical vulnerabilities across 390 Bitcoin-related projects.

The review also produced 4,962 potential risk reports, including 635 high-risk issues. Calle, the pseudonymous developer of the e-cash protocol Cashu who coordinated the effort, said: "The situation is very bad."

Thousands of potential risks were flagged

The audit was described as a broad health check for the Bitcoin ecosystem and involved 16 developers. Calle said the team used AI models to analyze Bitcoin wallets, cryptographic libraries, and various pieces of infrastructure. That process led to 4,962 reported potential risks, including 85 critical bugs and 635 high-risk issues.

The findings show how AI is becoming a practical tool in security research, while also exposing security weaknesses that have been sitting inside the Bitcoin ecosystem for a long time.

Disclosure, not detection, is the main challenge

Rob Hamilton, the developer who built the automated auditing system, said in a post on X that the hardest part is not identifying vulnerabilities. The bigger problem is how to deliver sensitive findings safely and accurately to the correct project maintainers.

Hamilton said: "The hardest part is coordination and disclosure, and then getting the vulnerabilities to the right people to handle them. This AI system is powerful and it did find critical flaws, but in terms of maturity, this is still only a '1.0 version.'"

Coldcard breach adds urgency

The report also linked the findings to the recent Coldcard cold wallet hack, which renewed concerns about the damage that can come from weaknesses in underlying software.

Since the Coldcard incident broke out on July 30, $114 million in user assets has been stolen. The report said the breach stemmed from a vulnerability that had been present in Coldcard firmware since 2021. If an attacker understood the affected private-key generation logic, the attacker could drain assets even without obtaining the user's physical cold wallet.

The case served as another reminder that assets stored in a cold wallet are not automatically safe for the long term if the software underneath contains unresolved flaws.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
570

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.