A volunteer Bitcoin security initiative says it used frontier AI models to scan 150 Bitcoin repositories and found more than a dozen vulnerabilities, as more developers turn to artificial intelligence to audit blockchain software.

About $20,000 spent on AI services
In a post on X earlier this week, AnchorWatch CEO Rob Hamilton said the group has spent about $20,000 on AI services while building what he called a “Bitcoin red team” platform.
“We have been working around the clock, with ~$20,000 of spend up to this point across different services,” Hamilton wrote. “Funding is secured, I appreciate all the gestures for donations but it is not necessary. The bill is taken care of.”
In cybersecurity, a red team tests software from an attacker’s perspective, looking for weaknesses before they are exploited.
Models used in the review effort
According to Hamilton, the Bitcoin red team uses Kimi K3 along with OpenAI’s GPT Sol, Anthropic’s Claude Fable and Opus models, and Z.ai’s GLM 5.2 to identify vulnerabilities and generate supporting documentation.
He added that the group had also connected with OpenAI for help getting Cyber Harness running.
“It's a much more expensive scan, but well worth it for load-bearing portions of the Bitcoin ecosystem and has already yielded good results,” he wrote.
Calle says reports were sent to several projects
Pseudonymous Bitcoin developer Calle said the initiative has built multiple AI-powered review systems aimed at wallets, cryptographic libraries, infrastructure, and other Bitcoin projects.
“We're averaging on the order of one critical exploit per hour per person,” Calle wrote on X. “We've reported critical vulnerabilities to several projects in the last 12 hours. Thankfully, this is a very expensive exercise. We're burning through $10,000 per day.”
The team did not disclose which projects were affected, and it did not provide details on the vulnerabilities.
Broader use of AI in crypto security
The announcement comes as AI is taking on a larger role in finding security flaws across the crypto sector. Earlier this year, researchers using Anthropic's Claude Opus 4.8 found a four-year-old flaw in Zcash that could have allowed attackers to create unlimited counterfeit ZEC.
In August, Coinkite said it believes attackers used AI to identify the Coldcard wallet vulnerability. Bitcoin bridge Boltz also suspended its swap service after saying attackers were using AI to identify vulnerabilities faster than its team could patch them.

