Overview
- The initiative has scanned roughly 150 Bitcoin repositories, revealing over a dozen vulnerabilities.
- Developers are creating an open-source AI platform specifically for auditing Bitcoin software.
- Critical vulnerabilities have been found in wallets, cryptographic libraries, and the broader infrastructure.
A volunteer security initiative has employed advanced AI models to examine 150 Bitcoin repositories, uncovering more than a dozen vulnerabilities as developers increasingly leverage artificial intelligence for blockchain audits.
In a recent post on X, Rob Hamilton, CEO of AnchorWatch, detailed that the group has invested approximately $20,000 in AI services while establishing a "Bitcoin red team" platform.
“We have been working tirelessly, with around $20,000 spent so far across various services,” he mentioned. “Funding is secured, and while I appreciate the offers for donations, it’s not necessary. The expenses are covered.”
A red team comprises cybersecurity experts who simulate attacks on software to identify vulnerabilities before they can be exploited.
According to Hamilton, the Bitcoin red team employs Kimi K3, OpenAI’s GPT Sol, and Anthropic’s Claude Fable and Opus models, as well as Z.ai’s GLM 5.2 to detect vulnerabilities and generate corresponding documentation.
“We have also collaborated with OpenAI to facilitate the operation of the Cyber Harness,” he added. “It’s a more costly scanning process, but it’s invaluable for critical components of the Bitcoin ecosystem and has already produced promising results.”
A pseudonymous Bitcoin developer known as Calle reported that the initiative has implemented several AI-driven review systems focused on wallets, cryptographic libraries, infrastructure, and other Bitcoin-related projects.
"We're averaging about one critical exploit per hour per person,” Calle stated on X. “In the last 12 hours, we’ve reported critical vulnerabilities to multiple projects. Fortunately, this effort is costly, with expenditures reaching $10,000 per day."
Specific projects affected and details regarding the vulnerabilities have not been disclosed by the team.
This announcement comes amid a rising trend of AI being utilized to detect security flaws within the cryptocurrency sector. Earlier this year, researchers utilizing Anthropic's Claude Opus 4.8 discovered a flaw in Zcash that had existed for four years, potentially allowing attackers to generate unlimited counterfeit ZEC. In August, Coinkite suggested that attackers might have exploited AI to identify vulnerabilities in the Coldcard wallet, while Bitcoin bridge Boltz halted its swap service after noting that attackers were using AI to find vulnerabilities more quickly than the team could address them.
