AI Bitcoin Security Audit Uncovers 85 Critical Vulnerabilities Across 390 Repositories » CoinEagle
Key Points
- Bitcoin Red Team found 85 critical flaws across 390 repositories within 27.5 hours.
- Audit followed Coldcard RNG exploit that caused over $100 million in losses.
A volunteer initiative known as the Bitcoin Red Team has reported thousands of vulnerabilities across open-source Bitcoin repositories during its first day of coordinated review.
The group, led by developer Calle and AnchorWatch CEO Rob Hamilton, logged 4,962 findings in 27.5 hours, including 85 critical and 635 high-severity issues.
More than $40,000 in artificial intelligence compute resources funded the effort, with financial support provided by OpenSats, a nonprofit supporting open-source Bitcoin development.
The audit followed a major security incident involving a random number generator flaw in Coldcard hardware wallets that resulted in over $100 million in confirmed losses.
Scope of the AI-Driven Security Review
The Red Team created a review harness covering 171,599 lines of code to identify foundational Bitcoin software libraries and document reproducible vulnerabilities.
According to project updates, 21.4% of the findings have been successfully reproduced so far.
Calle stated that the pace of discovery averaged roughly one critical exploit per hour per contributor during the early phase.
The team deployed multiple AI models, including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, to scan repositories and generate structured reports for maintainers.
Early restrictions on access to certain U.S.-based AI systems led the team to rely more heavily on Chinese open-source models before broader access was restored.
Hamilton indicated that the review harness is expected to be open-sourced, enabling companies to test both open- and closed-source Bitcoin codebases.
Coldcard Breach and Industry Response
The initiative was launched after attackers exploited a flaw in Coldcard’s RNG implementation, affecting MK3+ devices and enabling fund withdrawals.
Research identified at least 15 separate attackers who took advantage of the vulnerability before patched firmware was released.
Users who have not migrated funds to wallets generated under updated firmware may remain exposed.
Boltz exchange announced a temporary pause in certain operations as exchanges and service providers assessed potential AI-assisted vulnerability discoveries in the broader post-incident environment.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
US 30-year mortgage rate rises to nearly one-year high, homebuying demand remains under pressure
U.S. mortgage rates have risen for the fifth consecutive week, reaching their highest level this year.

Tango Therapeutics executive chair Barbara Weber steps down, exits board
Brady completes USD 1.4 billion acquisition of Honeywell productivity solutions unit
Columbus Acquisition extends WISeSat.Space merger deal deadline to Oct. 31, 2026
