Bitcoin Red Team Deploys AI to Uncover Critical Vulnerabilities Across 150 Repositories
A volunteer security group has scanned Bitcoin's core infrastructure using advanced AI models, discovering multiple critical exploits in wallets and infrastructure while establishing an open-source platform for automated security audits.
AI-Powered Vulnerability Discovery at Scale
A volunteer security initiative has launched a coordinated campaign to identify security flaws in Bitcoin’s ecosystem using frontier artificial intelligence models, uncovering multiple critical vulnerabilities across the cryptocurrency’s infrastructure in a matter of days. The effort, coordinated by AnchorWatch CEO Rob Hamilton and dubbed the Bitcoin Red Team, has scanned approximately 150 Bitcoin repositories and identified more than a dozen vulnerabilities affecting wallets, cryptographic libraries, and essential network infrastructure. The group has expended roughly $20,000 on AI services while constructing an open-source platform designed to automate software security audits.
The Bitcoin Red Team deployed multiple state-of-the-art AI models to conduct these audits, including Kimi K3, OpenAI’s GPT Sol, Anthropic’s Claude Fable and Opus models, and Z.ai’s GLM 5.2. According to Hamilton, the combination of these models has proven exceptionally effective at identifying previously unknown exploits. Bitcoin developer Calle disclosed that the team averages approximately one critical vulnerability discovery per hour for each team member engaged in the review process. The intensive effort requires roughly $10,000 in daily expenditures to sustain, though Hamilton indicated that funding for the initiative’s continued operation has already been secured.
Responsible Disclosure and Emerging Threats
Despite identifying critical vulnerabilities across multiple projects over a compressed timeframe, the Bitcoin Red Team has refrained from disclosing which specific projects were affected or providing detailed technical specifications of the discovered exploits. This cautious approach to vulnerability disclosure allows development teams adequate time to implement patches before public exposure of the flaws.
The Bitcoin Red Team’s work exemplifies a widening trend of artificial intelligence playing an increasingly significant role in identifying security weaknesses throughout the cryptocurrency industry. Earlier this year, researchers employing Anthropic’s Claude Opus 4.8 discovered a four-year-old vulnerability in Zcash that theoretically could have permitted the creation of counterfeit tokens. Hardware wallet manufacturer Coinkite has suggested that threat actors deployed AI to identify the Coldcard wallet vulnerability, while Bitcoin bridge protocol Boltz suspended its operations citing apprehension that attackers were leveraging AI systems to discover exploits faster than its engineering team could implement remediation.
Implications for Blockchain Security
The emergence of AI-powered security auditing represents both opportunity and challenge for blockchain projects. While initiatives like the Bitcoin Red Team employ these capabilities defensively to strengthen security postures, identical tools can be weaponized by malicious actors. The velocity at which critical vulnerabilities can now be identified—measured in single-digit hours—underscores the urgency for blockchain projects to implement continuous, AI-assisted security reviews as standard practice. For the broader cryptocurrency ecosystem, this trend emphasizes that conventional development methodologies may no longer suffice; the security baseline has fundamentally escalated, demanding persistent vigilance powered by machine learning. The acceleration of both defensive and offensive security capabilities will likely catalyze significant infrastructure improvements across blockchain networks, directly benefiting users and projects that prioritize security-first development practices.
Source: Bitcoin Red Team, via Decrypt. Not financial advice.