A volunteer team utilizing AI to analyze Bitcoin codebases reports an alarming rate of critical bugs, averaging one per hour per developer, costing around $10,000 daily in computational resources.
By Shaurya Malwa|Edited by Omkar GodboleUpdated Aug 6, 2026, 7:53 a.m. Published Aug 6, 2026, 7:14 a.m. 2 min readMake preferred on ShareShare this articleCopy linkX (Twitter)LinkedInFacebookEmailMake preferred on Bitcoin developers identify 85 serious bugs amidst security concerns. (Unsplash)SummaryShow- In just 24 hours, a group of 16 Bitcoin developers utilized AI tools to uncover 4,962 security vulnerabilities across 390 projects.
- The audit revealed 85 critical and 635 high-severity bugs, posing significant challenges for project maintainers.
- This situation underscores the transformative impact of AI on security research for both developers and potential attackers.
A volunteer group has uncovered 85 serious bugs across 390 Bitcoin BTC$64,785.85 projects in just over a day.
This coordinated security audit, involving 16 Bitcoin developers, resulted in 4,962 findings, including 85 critical and 635 high-severity vulnerabilities, as noted by Calle, the pseudonymous developer behind the Cashu ecash protocol.
The results stem from an audit where developers employed AI models to scrutinize Bitcoin wallets, cryptographic libraries, and infrastructure.
"The situation is extremely bad," Calle remarked.
We are ramping up our efforts.
— Calle (@callebtc) August 5, 2026
Although much of our work still requires manual intervention (guiding the AI), our automated systems are improving concurrently.
Allowing everyone to use their preferred review methods has been the most effective approach so far.
We’re experiencing a lot of… pic.twitter.com/EoS6Z9ubpr
According to Calle, most critical reports have been verified swiftly by project maintainers, with a working proof of concept being created in a local testing environment prior to submission.
However, the sheer volume of findings is causing its own set of complications.
"There's a lot of chaos in the ecosystem right now," he expressed, apologizing to maintainers inundated with reports and noting that the group is still figuring out how to manage “the slop.”
The group is able to publish findings quickly, as maintainers can validate results almost at no cost using the same tools, Calle explained, adding that "others not on the red team will likely discover the same issues we did."
Rob Hamilton, who is developing the automated system for the group, mentioned in a post on X that the challenge lies not in identifying bugs, but in directing them to the appropriate maintainers.
"The toughest part is coordinating to ensure the right people receive the information," Hamilton stated. "While it is powerful to have identified critical issues, I see this as just the first version of our efforts."
This audit comes as the ecosystem grapples with the repercussions of vulnerabilities being discovered by malicious actors first.
The Coldcard sweeps, which commenced on July 30 and have siphoned off up to $114 million from wallets with seeds generated by defective firmware, originated from a bug that had been dormant since 2021 and required no access to the physical device once the affected key space was known.
However, attackers are already equipped with similar tools.
Anthropic noted in April that one of its AI models, withheld from public release and shared only with trusted users, uncovered a bug that had gone unnoticed in widely used software for 27 years, costing less than $50 to identify. This flaw was found in the encryption software securing banking connections, exchange logins, and the servers powering much of the internet.
In a separate instance, Google's threat intelligence team reported in May that it had intercepted a criminal group preparing an attack based on a vulnerability that one of its models had detected for them.
Related AssetsBitcoin$64,785.851.05%Latest Crypto News- 1Live updates: Bitcoin nears $65,000 as oil, inflation hopes keep macro bid alive34 minutes ago
- 2S&P 500 has added crypto's $2 trillion market cap this month. Bitcoin is not impressed. Here's why1 hour ago
- 3Bitcoin steadies above $64,000 as traders watch $100 billion SpaceX unlock3 hours ago
- 4XRP whales keep buying the dip, but ether shows deeper capitulation3 hours ago
- 5CASHCAT jumps 120% in a week as Robinhood Chain hits $774 million of value locked3 hours ago
- 6Here are the possible outcomes for Clarity right now4 hours ago
- 7Crypto firm RedotPay says it will defend itself ‘vigorously’ against Binance lawsuit10 hours ago
- 8Crypto's campaign efforts see rare loss, but crypto roster in Congress likely to grow13 hours ago
- 9Coldcard exploit could boost demand for regulated bitcoin exposure, analysts say16 hours ago
- 10Crypto Long & Short: Putting the bitcoin sizing question to the test16 hours ago
The Evolution of the Crypto CEX Landscape: A Case Study on Binance
The Evolution of the Crypto CEX Landscape: A Case Study on Binance
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
By CoinDesk ResearchJun 29, 2026Commissioned byBinanceBinance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Why it matters:
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
View Full ReportMore From Tech