A volunteer group deploying AI models to scan Bitcoin codebases says it is uncovering roughly one critical vulnerability per person per hour, with compute costs running close to $10,000 per day. In just over a day, the team flagged 85 critical bugs across 390 Bitcoin-related projects.
The coordinated effort, involving 16 developers, has produced 4,962 total findings, including 85 critical and 635 high-severity issues, according to Calle, the pseudonymous developer behind the Cashu ecash protocol.
The audit relies on AI-driven analysis of Bitcoin wallets, cryptographic libraries, and supporting infrastructure. Calle described the situation bluntly as “extremely bad,” adding that the team is rapidly expanding its efforts. While much of the process still requires manual oversight, automated tools are improving, and allowing contributors to use their own review methods has proven effective.
Most of the critical issues have already been validated by project maintainers, who are reproducing them locally using proof-of-concept setups before addressing them. However, the sheer volume of findings is creating its own strain.
“There’s a lot of chaos right now in the ecosystem,” Calle said, noting that maintainers are being flooded with reports. He added that the team is still refining how to filter out low-quality or redundant findings.
The group is publishing results quickly, arguing that maintainers can now verify issues cheaply using similar tools and that other researchers are likely to uncover the same vulnerabilities anyway.
Rob Hamilton, who is building the automation system behind the effort, said the primary bottleneck is no longer finding bugs but getting them to the right developers. “The hardest part is coordination,” he said, describing the current setup as an early-stage system.
The audit comes as the ecosystem is already dealing with the fallout from missed vulnerabilities. The Coldcard wallet exploit, which began July 30, has led to losses of up to $114 million and was traced to a firmware flaw dating back to 2021. Once attackers identified the weak key space, they were able to drain affected wallets without needing physical access.
At the same time, attackers have access to similar AI tools. In April, Anthropic revealed that one of its restricted models discovered a decades-old bug in widely used software for less than $50. The flaw had gone unnoticed for 27 years and affected encryption systems used in banking, exchange logins, and core internet infrastructure.
In a separate incident, Google’s threat intelligence team said in May it had intercepted a criminal group preparing an attack based on a vulnerability identified using AI.
Together, these developments underscore a growing reality: the same AI tools accelerating security research are also lowering the barrier for exploitation, intensifying the race between defenders and attackers across the Bitcoin ecosystem.

































