Bitcoin (BTC) developers reported 85 critical flaws after an AI-assisted audit produced 4,962 findings across 390 projects in just over 24 hours.
Key Points:
- The audit found 85 critical and 635 high-severity issues.
- The volunteer effort is averaging about one critical bug per person each hour, with compute costs near $10,000 daily.
- Developers say verification and routing, not discovery, have become the main challenge as AI lowers the cost of finding flaws.
Bitcoin Bug Audit
Sixteen developers joined the coordinated review, directing AI models at wallets, cryptographic libraries and other infrastructure. The group filed 4,962 findings across 390 projects, according to Calle, the pseudonymous developer behind the Cashu ecash protocol.
Calle called the situation “extremely bad.” Project owners quickly confirmed most critical reports, while researchers reproduced working proofs of concept in local test environments before sending details to maintainers. The audit also identified 635 high-severity issues, adding to the workload facing volunteer teams and project operators.
The pace is unusually high, with the group averaging about one critical bug per person each hour and spending roughly $10,000 a day on computing power.
The volume has created confusion. Calle said volunteers must separate valid findings from low-quality output, but the group publishes quickly because maintainers can verify reports cheaply and attackers may discover the same flaws.
Also Read: Meta's Muse Code Undercuts Anthropic And OpenAI At $1.25 Per Million Input Tokens
Calle Security Warning
Rob Hamilton, who is building the automated audit setup, said finding vulnerabilities is no longer the main bottleneck. Routing is now the hardest task. “The hardest part is coordinating to get things to the right people,” he wrote, while describing the current system as only a first version.
That shift matters because AI sharply reduces the time and money needed to uncover old software weaknesses. Anthropic said in April that a restricted model found a 27-year-old flaw in widely used software. The cost was below $50.
Google reported a separate case in May, when its threat intelligence team found a criminal group preparing an attack around a flaw identified with an AI model. Attackers already have comparable tools.
The audit follows the Coldcard wallet thefts that began July 30 and reached as much as $114 million after attackers exploited faulty firmware without accessing physical devices. The underlying bug had remained dormant since 2021.
Read Next: Bitcoin Whales Rebuild Holdings After $60K Dip, But Bottom Is Unclear





