5 Sources
[1]
Bitcoin Red Team Says AI Is Finding Critical Exploits Across Core Projects
Developers say the effort is uncovering critical vulnerabilities across wallets, cryptographic libraries, and infrastructure. A volunteer security initiative says it used frontier AI models to scan 150 Bitcoin repositories and found more than a dozen vulnerabilities as developers increasingly use
[2]
Ledger Says Coldcard Exploit Shows Bitcoin Wallet Security Must Adapt to AI
Ledger says AI is accelerating vulnerability discovery and forcing security teams to defend at machine speed. Hardware wallet maker Ledger says the recent Coldcard exploit should serve as a warning for the cryptocurrency industry. According to Ledger CTO Charles Guillemet, the incident exposed
[3]
Crypto Companies Urge AI Firms to Give Bitcoin Devs Early Access
The Bitcoin Policy Institute and other industry participants urged AI companies to offer early access to their frontier models to aid Bitcoin and open-source developers in their cybersecurity efforts. A group of cryptocurrency companies has urged frontier artificial intelligence (AI) labs to give
[4]
Bitcoin Researcher Turns to Chinese AI after OpenAI Restricts Access
Bitcoin Red Team has now found 1,288 critical and high-level vulnerabilities in the Bitcoin ecosystem as of Saturday. A Bitcoin security researcher says he has been forced to go back to using open-source Chinese AI models after finding himself restricted from analyzing further codebases by OpenAI,
[5]
How AI Test Rediscovered a Bitcoin Bug that Could Have Led to Theft
The findings also highlight a shift in how may evolve. Much of the industry's long-term focus has been on quantum computing, which could eventually threaten Bitcoin's cryptographic foundations. AI presents a more immediate challenge because it can already identify mistakes in wallet firmware,
Share
Copy Link
A volunteer Bitcoin Red Team used frontier AI models to scan 150 repositories and found 1,288 critical vulnerabilities across wallets and cryptographic libraries. The initiative spent $20,000 on AI services and uncovered exploits at a rate of one critical flaw per hour, but researchers face access restrictions from major AI providers.

A volunteer security initiative known as the Bitcoin red team has uncovered 1,288 critical and high-level Bitcoin vulnerabilities using frontier AI security tools, raising urgent questions about how defenders can keep pace with attackers in an AI-accelerated threat landscape
1
. Led by AnchorWatch CEO Rob Hamilton, the group spent approximately $20,000 scanning 150 Bitcoin repositories with advanced AI models including Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable and Opus models, and Z.ai's GLM 5.21
. The team reported finding exploits at an alarming rate of one critical vulnerability per hour per person, burning through $10,000 per day in AI-driven vulnerability discovery efforts1
.The initiative targeted wallets, cryptographic libraries, infrastructure, and other Bitcoin projects, reporting critical vulnerabilities to several projects within 12 hours of discovery
1
. Pseudonymous Bitcoin developer Calle noted the expensive nature of this AI-assisted code review, emphasizing that high costs currently limit widespread exploitation by malicious actors1
. The team did not disclose which specific projects were affected to allow developers time to patch vulnerabilities before public disclosure.The urgency of AI for securing open-source infrastructure became painfully clear following the Coldcard hardware wallet exploit, which resulted in approximately $130 million in Bitcoin theft
2
. Coinkite disclosed a flaw in the air-gapped Coldcard Bitcoin hardware wallet dating back to a March 2021 firmware build2
. The vulnerability used a software fallback instead of the device's hardware random number generator for private key generation, making wallet recovery seeds guessable2
. Coinkite believes attackers used AI to identify the vulnerability that had sat undetected in public code for over five years2
.Ledger CTO Charles Guillemet warned that the incident exposed critical weaknesses in how some hardware wallet devices generate cryptographic randomness
2
. He emphasized that AI is changing cybersecurity by allowing attackers to scan code and identify vulnerabilities at machine speed, forcing defenders to operate at the same pace2
. Guillemet noted that open source and reviewed code are not the same thing, highlighting that public visibility does not guarantee thorough security audits2
. Ledger confirmed its own hardware wallets were not affected because they draw root secrets from a true hardware random number generator built into a certified Secure Element with no software fallback path2
.The Bitcoin Policy Institute and multiple cryptocurrency companies issued an open letter urging frontier AI labs to establish trusted-access programs for qualified defenders of open-source financial infrastructure
3
. The letter, co-signed by organizations including Anchorage Digital, BitGo, Bitwise, Blockstream, MARA, Kraken, Ledger and Trezor, noted that many digital asset defenders lack access to lab cyber programs and face guardrails on publicly available frontier systems3
. This forces open-source developers to rely on less capable open-weight models while sophisticated attackers potentially use more advanced tools3
.The letter emphasized that open-source software supports critical digital and financial infrastructure, with Bitcoin alone securing more than $1 trillion in value
3
. It warned that vulnerabilities in open-source infrastructure can place life savings at risk, making AI security tools essential for Bitcoin wallet security3
. The Bitcoin Policy Institute reported receiving multiple independent reports from open-source maintainers describing sophisticated actors, including potential foreign adversaries, using advanced AI capabilities to sustain attacks3
. Hacking activity surged in April 2026, with malicious actors stealing over $634 million from cryptocurrency platforms3
.Related Stories
Rob Hamilton revealed he was forced to return to using open-source Chinese AI models after finding his access to OpenAI's Trust & Cyber capabilities restricted
4
. Hamilton had begun integrating OpenAI capabilities into his Bitcoin Red Team work on Saturday, only to discover his access blocked the following morning4
. He expressed frustration as a patriotic American being forced to use Chinese models to protect Bitcoin infrastructure4
. The restriction prevented him from continuing investigations to verify code changes and discover additional vulnerabilities4
.Hamilton warned that this policy asymmetry creates a dangerous situation where intelligence remains unrestricted for malicious actors who ignore rules, while those engaged in harm reduction are left on the sidelines
4
. The incident highlights growing concerns that the most capable AI tools aren't being made available to defenders conducting vulnerability research4
. Last month, crypto executives indicated that many of crypto's biggest players are still waiting to gain access to powerful new AI models to strengthen their code from attacks, with only a select few having obtained it4
.The findings highlight a fundamental shift in how Bitcoin wallet security may evolve beyond the industry's traditional focus on quantum computing threats
5
. AI presents a more immediate challenge because it can already identify mistakes in wallet firmware, random-number generation, key management, and cryptographic implementations without breaking Bitcoin's underlying encryption5
. The Coldcard incident demonstrated that even users doing everything right by storing digital assets in offline hardware wallets remain dependent on the quality of the wallet's firmware and cryptographic implementation5
.For developers, AI finding critical exploits represents both a defensive and offensive tool that enables wallet manufacturers to repeatedly scan legacy firmware as newer AI models become available, while attackers can automate vulnerability discovery across older software releases at minimal cost
5
. The experiment underscores that security reviews can no longer be treated as one-time events5
. As AI models become faster, cheaper, and more capable, continuous code auditing, responsible disclosure programs, and rapid patch deployment will become essential for protecting digital assets5
. Ledger reported spending the past two years using AI alongside human security engineers and cryptographers to review code and identify vulnerabilities before attackers can exploit them2
.Summarized by
Navi
[3]
[4]
[5]
15 Apr 2026•Technology

27 May 2026•Technology

07 Apr 2026•Technology

1
Science and Research

2
Technology

3
Technology
