This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$63,826+0.65%ETH$1,895+0.92%SOL$76.36+1.06%XRP$1.01+0.87%DOGE$0.0707+1.63%ADA$0.1841+0.96%Total Cap$2.29T+0.28%Layer Index41 Neutral
External ReportingUpdated 5 天前

Bitcoin AI Security Audit Files 4,962 Findings Across 390 Projects

A volunteer group is pointing AI agents at Bitcoin project codebases and says 720 of the issues it has filed are high severity or critical.

Bitcoin AI Security Audit Files 4,962 Findings Across 390 Projects
作者 Decrypt Agent 2 分钟阅读
Image via Decrypt

Market Context

Bitcoin

BTC

$63,826

+0.65% 24h

Layer Index

41

↑ 6 pts in 24h

In brief

  • Cashu creator calle said the campaign logged 85 critical and 635 high-severity issues in its first 30 hours.
  • Contributors each prompt their own agents, which the group says produces a wider spread of hits than a single method would.
  • Privacy and coinjoin projects carried the highest share of serious findings, at 24%.

A volunteer group calling itself the Bitcoin Red Team has filed 4,962 security findings across 390 Bitcoin projects in roughly 30 hours, running what it describes as a “large-scale ecosystem audit” with AI agents doing much of the scanning.

Pseudonymous developer calle, who created the Bitcoin ecash protocol Cashu, published the campaign's first situation report on Wednesday. It puts 85 findings at critical severity and 635 at high, together 14.5% of the corpus and an average of 1.85 serious issues per project, filed at 166 findings an hour. He said the team has grown to 16 people working around the clock; the report logs 17 contributors, 14 of them human and three automated.

Much of the work is still manual, "hand holding the AI," calle wrote, though automated harnesses are improving, and 91% of findings arrived through automated scan intake. Letting everyone use their own preferred review method "has proven to be the most effective strategy," he said, because contributors prompt their agents differently and turn up different bugs. Around 21% of findings have been dynamically reproduced with proof-of-concept code.

The severity spread varies sharply by category. Privacy and coinjoin tools returned the highest proportion of high-or-critical findings at 24%, followed by swaps and exchanges at 21% and payments and merchant tools at 17%. Cryptographic libraries and SDKs produced the largest raw volume at 1,101 findings, but only 10% cleared the high bar.

Maintainers are getting flooded

Only 19 projects, under 5% of those reviewed, have had findings disclosed upstream so far, and calle acknowledged the campaign is adding to a difficult moment for maintainers.

"We're sincerely sorry if our reports added stress to your already stressful day," he wrote, while arguing the findings should go out fast because project owners are best placed to validate them, validation is now nearly free with AI, and anyone else running the same tools will reach the same bugs. Eight findings have been retired as false positives.

The Coldcard backdrop

The campaign lands as Bitcoin's security assumptions come under scrutiny. Coinkite's Coldcard wallet lost users some $130 million after a March 2021 firmware build drew wallet seeds from a software fallback rather than the device's hardware random number generator, leaving private keys guessable. In a post-mortem, the firm noted it was likely that "someone used AI to review previous versions of our firmware."

Ledger chief technology officer Charles Guillemet told Decrypt on Tuesday that the incident showed AI was now being used to identify vulnerabilities in crypto code "at machine speed." He added that "open source and reviewed are not the same thing," noting the Coldcard flaw sat in public code for more than five years until an adversary reportedly used AI to find it. Defence, he argued, now has to move at the same speed as attackers—as groups like the Bitcoin Red Team are demonstrating.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Follow the Story

  1. Aug 6Bitcoin AI Security Audit Files 4,962 Findings Across 390 Projects
  2. Aug 13Bitcoin falls below $63,500 as US inflation mee...
  3. Aug 13Bitcoin price steadies near $64K as HYPE leads crypto gainers
  4. Aug 13Surge of 57 Million Addresses: Macro Shifts End Bitcoin Bear Market

Attribution

Originally reported by Decrypt

Get stories like this, daily.

Daily crypto + regulation intelligence, straight to your inbox. Free.

相关报道