AI Security Tools Uncover Over 1,200 Critical Bitcoin Vulnerabilities in Days

5 Sources

Share

A volunteer Bitcoin Red Team used frontier AI models to scan 150 repositories and found 1,288 critical vulnerabilities across wallets and cryptographic libraries. The initiative spent $20,000 on AI services and uncovered exploits at a rate of one critical flaw per hour, but researchers face access restrictions from major AI providers.

News article

AI in Cybersecurity Exposes Widespread Bitcoin Vulnerabilities

A volunteer security initiative known as the Bitcoin red team has uncovered 1,288 critical and high-level Bitcoin vulnerabilities using frontier AI security tools, raising urgent questions about how defenders can keep pace with attackers in an AI-accelerated threat landscape

1

. Led by AnchorWatch CEO Rob Hamilton, the group spent approximately $20,000 scanning 150 Bitcoin repositories with advanced AI models including Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable and Opus models, and Z.ai's GLM 5.2

1

. The team reported finding exploits at an alarming rate of one critical vulnerability per hour per person, burning through $10,000 per day in AI-driven vulnerability discovery efforts

1

.

The initiative targeted wallets, cryptographic libraries, infrastructure, and other Bitcoin projects, reporting critical vulnerabilities to several projects within 12 hours of discovery

1

. Pseudonymous Bitcoin developer Calle noted the expensive nature of this AI-assisted code review, emphasizing that high costs currently limit widespread exploitation by malicious actors

1

. The team did not disclose which specific projects were affected to allow developers time to patch vulnerabilities before public disclosure.

Coldcard Exploit Demonstrates AI's Role in Cybersecurity Attacks

The urgency of AI for securing open-source infrastructure became painfully clear following the Coldcard hardware wallet exploit, which resulted in approximately $130 million in Bitcoin theft

2

. Coinkite disclosed a flaw in the air-gapped Coldcard Bitcoin hardware wallet dating back to a March 2021 firmware build

2

. The vulnerability used a software fallback instead of the device's hardware random number generator for private key generation, making wallet recovery seeds guessable

2

. Coinkite believes attackers used AI to identify the vulnerability that had sat undetected in public code for over five years

2

.

Ledger CTO Charles Guillemet warned that the incident exposed critical weaknesses in how some hardware wallet devices generate cryptographic randomness

2

. He emphasized that AI is changing cybersecurity by allowing attackers to scan code and identify vulnerabilities at machine speed, forcing defenders to operate at the same pace

2

. Guillemet noted that open source and reviewed code are not the same thing, highlighting that public visibility does not guarantee thorough security audits

2

. Ledger confirmed its own hardware wallets were not affected because they draw root secrets from a true hardware random number generator built into a certified Secure Element with no software fallback path

2

.

Industry Calls for AI Access to Defend Open-Source Developers

The Bitcoin Policy Institute and multiple cryptocurrency companies issued an open letter urging frontier AI labs to establish trusted-access programs for qualified defenders of open-source financial infrastructure

3

. The letter, co-signed by organizations including Anchorage Digital, BitGo, Bitwise, Blockstream, MARA, Kraken, Ledger and Trezor, noted that many digital asset defenders lack access to lab cyber programs and face guardrails on publicly available frontier systems

3

. This forces open-source developers to rely on less capable open-weight models while sophisticated attackers potentially use more advanced tools

3

.

The letter emphasized that open-source software supports critical digital and financial infrastructure, with Bitcoin alone securing more than $1 trillion in value

3

. It warned that vulnerabilities in open-source infrastructure can place life savings at risk, making AI security tools essential for Bitcoin wallet security

3

. The Bitcoin Policy Institute reported receiving multiple independent reports from open-source maintainers describing sophisticated actors, including potential foreign adversaries, using advanced AI capabilities to sustain attacks

3

. Hacking activity surged in April 2026, with malicious actors stealing over $634 million from cryptocurrency platforms

3

.

Access Restrictions Force Researchers Toward Chinese AI Models

Rob Hamilton revealed he was forced to return to using open-source Chinese AI models after finding his access to OpenAI's Trust & Cyber capabilities restricted

4

. Hamilton had begun integrating OpenAI capabilities into his Bitcoin Red Team work on Saturday, only to discover his access blocked the following morning

4

. He expressed frustration as a patriotic American being forced to use Chinese models to protect Bitcoin infrastructure

4

. The restriction prevented him from continuing investigations to verify code changes and discover additional vulnerabilities

4

.

Hamilton warned that this policy asymmetry creates a dangerous situation where intelligence remains unrestricted for malicious actors who ignore rules, while those engaged in harm reduction are left on the sidelines

4

. The incident highlights growing concerns that the most capable AI tools aren't being made available to defenders conducting vulnerability research

4

. Last month, crypto executives indicated that many of crypto's biggest players are still waiting to gain access to powerful new AI models to strengthen their code from attacks, with only a select few having obtained it

4

.

AI Rediscovering Bitcoin Bug Signals Shift in Security Paradigm

The findings highlight a fundamental shift in how Bitcoin wallet security may evolve beyond the industry's traditional focus on quantum computing threats

5

. AI presents a more immediate challenge because it can already identify mistakes in wallet firmware, random-number generation, key management, and cryptographic implementations without breaking Bitcoin's underlying encryption

5

. The Coldcard incident demonstrated that even users doing everything right by storing digital assets in offline hardware wallets remain dependent on the quality of the wallet's firmware and cryptographic implementation

5

.

For developers, AI finding critical exploits represents both a defensive and offensive tool that enables wallet manufacturers to repeatedly scan legacy firmware as newer AI models become available, while attackers can automate vulnerability discovery across older software releases at minimal cost

5

. The experiment underscores that security reviews can no longer be treated as one-time events

5

. As AI models become faster, cheaper, and more capable, continuous code auditing, responsible disclosure programs, and rapid patch deployment will become essential for protecting digital assets

5

. Ledger reported spending the past two years using AI alongside human security engineers and cryptographers to review code and identify vulnerabilities before attackers can exploit them

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved