A team of programmers, led by Calle, the anonymous developer behind the Cashu digital currency protocol, identified 85 critical security vulnerabilities within 390 Bitcoin (BTC) projects after 27.5 hours of scanning. The team documented a total of 4,962 issues, including 85 critical and 635 high-severity vulnerabilities.
This extensive scan combined human expertise with AI models to audit Bitcoin wallets, cryptographic libraries, and related infrastructure. The programmers employed Moonshot's Kimi K3 model, an AI tool based in China. OpenSats, a non-profit organization dedicated to developing open-source BTC, funded the operation, which incurred over 40,000 USD in AI computing costs.
According to Calle, development teams swiftly confirmed most critical vulnerabilities. However, the sheer volume of discoveries has presented significant challenges. "The ecosystem is quite chaotic right now," Calle stated, apologizing to the development teams now overwhelmed with reports.
![]() |
A symbolic Bitcoin coin placed on electronic circuit boards. *Photo: CNBC* |
This comprehensive audit comes as the Bitcoin community grapples with the aftermath of a recent attack on Coldcard cold wallets. Since July 30, hackers have stolen up to 114 million USD in Bitcoin from wallets using faulty Coldcard firmware. This vulnerability, quietly present since 2021, allowed attackers to gain remote access to wallets by recreating the recovery phrase (seed phrase).
Experts warn that the Coldcard incident underscores a critical shift: Bitcoin security is no longer a "set it and forget it" task. As cyber threats, especially those augmented by AI, grow more sophisticated, users face a choice. They must either continuously monitor for new risks or entrust their assets to professional custodians with dedicated security teams. Analysts suggest that malicious actors already possess AI tools similar to those used in the Coldcard attack.
The growing capability of AI in uncovering vulnerabilities is evident in other recent cases. In April, Anthropic reported that one of its AI models, currently in limited release to selected users, discovered a 27-year-old flaw in one popular software for under 50 USD. This vulnerability impacted encryption software vital for protecting banking connections, exchange accounts, and servers across much of the Internet. In May, Google's cyber security intelligence team announced it had detected a criminal group preparing an attack based on a vulnerability also found by AI.
Tieu Gu (according to CoinDesk, Forbes)
