Kimi K3 flags 4,962 flaws in 24-hour Bitcoin ecosystem audit as Coldcard fallout deepens

Kimi K3 flags 4,962 flaws in 24-hour Bitcoin ecosystem audit as Coldcard fallout deepens

N
News Editor
2026-08-08 10:40:10
Bitcoin developers say an AI-assisted security sweep has exposed thousands of weaknesses across the broader ecosystem just as the fallout from the Coldcard wallet exploit continues to unsettle users and traders. A volunteer team said it scanned about 390 Bitcoin-related projects in roughly 24 hours and found 4,962 security issues, including 85 critical bugs and 635 high-severity flaws, calling the state of ecosystem security "extremely bad." The group, now 16 people working in shifts around the clock, is using Moonshot’s open-weight Kimi K3 model, with daily compute costs of about $10,000 covered by OpenSats. At the same time, Coldcard is still urging users to move funds after an exploit tied to a five-year-old key-generation defect led to the theft of nearly 2,000 BTC from more than 5,200 addresses over several days. One wallet linked to the attacker still holds about $36 million in bitcoin, while on-chain messages sent to that address include pleas for the funds to be returned and at least one message offering laundering services for a 10% fee. The overlap between AI-powered defense and AI-assisted exploitation has become a central concern.

Bitcoin’s security concerns are widening on two fronts at once: developers are uncovering flaws at scale, while the fallout from the Coldcard exploit is still playing out.

A volunteer group of Bitcoin developers said it used AI tools to scan about 390 Bitcoin-related projects in roughly 24 hours and found 4,962 security vulnerabilities. That tally included 85 critical flaws and 635 high-severity issues. The team described the ecosystem’s security condition in blunt terms: "extremely bad."

A 16-person team is running the audit with Kimi K3

The effort is being carried out by a volunteer team of Bitcoin developers. Calle, the pseudonymous developer of the Cashu ecash protocol, wrote on X that the group has grown to 16 people, spread across the world and working in round-the-clock shifts.

"We have grown to 16 people, globally distributed, around-the-clock shifts," Calle wrote. "We are conducting a large-scale ecosystem security audit of Bitcoin codebases."

According to Calle, the team is using Moonshot’s Kimi K3 model, an open-weight artificial intelligence tool from China. Daily compute spending is about $10,000, with OpenSats covering the bill.

The developers said most of the discovered issues have already been validated by the affected projects. One developer said the pace works out to roughly one critical bug found per hour, a sign of how quickly the audit is surfacing serious problems.

Rob Hamilton, chief executive of Bitcoin insurance company AnchorWatch and one of the audit participants, also wrote on X that the team had found some "critical issues" and said the work had been continuing day and night.

Coldcard exploit keeps users and traders on edge

The security sweep comes after the Coldcard incident, which the report said left Bitcoin and crypto traders shaken by an attack valued at about $100 million. The episode briefly fueled fears of another sharp market drop.

Since the first reports of the Coldcard breach emerged, bitcoin has rebounded, but the report said it remains near recent lows. Traders are still watching for another shock.

Last week, the Coldcard Bitcoin hardware wallet was hit by an exploit that drained nearly 2,000 BTC from more than 5,200 addresses over a span of several days, with the stolen amount valued at just over $100 million in the report. The attacker exploited a key-generation defect that had existed for five years.

Coldcard urges immediate fund migration

The Coldcard team has urged users to move their funds and repeatedly asked people on social media to help spread the warning.

The company’s official account wrote: "Please treat this as an emergency. Move your funds immediately. Follow the guidance for your device model, upgrade the device, generate a new seed, and carefully move funds ... the threat is ongoing."

One wallet tied to the hacker still holds about $36 million in bitcoin, most of which is believed to be stolen proceeds. Since the incident became public, that address has continued to receive transfers, some of them carrying messages through Bitcoin’s OP_RETURN function.

One message read: "I launder BTC, do KYC and cash out. I charge 10%." The report said that was interpreted as a solicitation for money laundering, aimed at turning the hacker into a client. Other messages directly asked for the stolen bitcoin to be returned.

AI is speeding up both defense and exploitation

An on-chain analyst said the vulnerability is now public, the case is drawing intense attention, and frontier large models are widely accessible. In that analyst’s view, multiple hacking teams may already be studying the same weakness at the same time in an effort to expand the damage. "You are racing against time."

Cobra, the pseudonymous co-owner of Bitcoin.org, said he had a "very bad feeling" and argued that AI may already have played a role in the draining of Coldcard funds.

The report said the AI-driven bug sweep and the earlier Coldcard theft are pushing Bitcoin ecosystem security toward a new breaking point. Developers are using AI to accelerate bug discovery. Attackers may be using the same class of tools to speed up exploitation. That leaves a narrower window for fixes and for users to move assets.

Bitcoin is still trading near recent lows, with traders waiting for the next possible shock, according to the report. The audit, which is burning about $10,000 a day in compute, may only be the start of a broader security review across the ecosystem.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
510

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.