A 16-member team of Bitcoin developers used AI models to run a large-scale security audit and found 85 critical vulnerabilities across 390 Bitcoin-related projects.
The review also produced 4,962 potential risk reports, including 635 high-risk issues. Calle, the pseudonymous developer of the e-cash protocol Cashu who coordinated the effort, said: "The situation is very bad."
Thousands of potential risks were flagged
The audit was described as a broad health check for the Bitcoin ecosystem and involved 16 developers. Calle said the team used AI models to analyze Bitcoin wallets, cryptographic libraries, and various pieces of infrastructure. That process led to 4,962 reported potential risks, including 85 critical bugs and 635 high-risk issues.
The findings show how AI is becoming a practical tool in security research, while also exposing security weaknesses that have been sitting inside the Bitcoin ecosystem for a long time.
Disclosure, not detection, is the main challenge
Rob Hamilton, the developer who built the automated auditing system, said in a post on X that the hardest part is not identifying vulnerabilities. The bigger problem is how to deliver sensitive findings safely and accurately to the correct project maintainers.
Hamilton said: "The hardest part is coordination and disclosure, and then getting the vulnerabilities to the right people to handle them. This AI system is powerful and it did find critical flaws, but in terms of maturity, this is still only a '1.0 version.'"
Coldcard breach adds urgency
The report also linked the findings to the recent Coldcard cold wallet hack, which renewed concerns about the damage that can come from weaknesses in underlying software.
Since the Coldcard incident broke out on July 30, $114 million in user assets has been stolen. The report said the breach stemmed from a vulnerability that had been present in Coldcard firmware since 2021. If an attacker understood the affected private-key generation logic, the attacker could drain assets even without obtaining the user's physical cold wallet.
The case served as another reminder that assets stored in a cold wallet are not automatically safe for the long term if the software underneath contains unresolved flaws.

