NewsCryptoBitcoin Red Team Leverages AI to Uncover Critical Vulnerabilities Across Core Projects

Bitcoin Red Team Leverages AI to Uncover Critical Vulnerabilities Across Core Projects

Author: Decrypt·

Key Takeaways

  • A volunteer security team has scanned approximately 150 Bitcoin repositories using frontier AI models, resulting in over a dozen vulnerability disclosures.
  • The initiative has spent roughly $20,000 on AI services to date, with ongoing costs of approximately $10,000 per day.
  • The red team employs multiple AI models including Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable and Opus models, and Z.ai's GLM 5.2 to identify system vulnerabilities and generate supporting documentation.
  • The developers did not disclose specific affected projects or technical details, following responsible disclosure practices to allow maintainers time to patch issues.
  • AI-assisted security audits are becoming increasingly critical across the crypto sector as recent incidents involving Zcash, Coldcard, and Boltz demonstrate that both attackers and defenders now leverage similar AI capabilities.
Bitcoin Red Team Leverages AI to Uncover Critical Vulnerabilities Across Core Projects

A volunteer security initiative reports that it has utilized frontier artificial intelligence models to scan approximately 150 Bitcoin repositories, resulting in more than a dozen vulnerability disclosures. The effort highlights how developers are increasingly relying on AI to audit blockchain infrastructure that secures hundreds of billions of dollars in value.

In a recent post on X, AnchorWatch CEO Rob Hamilton stated that the group has spent roughly $20,000 on AI services to construct a "Bitcoin red team" platform. A red team typically consists of cybersecurity professionals who evaluate software from an attacker's perspective, proactively searching for vulnerabilities before they can be exploited.

“We have been working around the clock, with ~$20,000 of spend up to this point across different services,” Hamilton wrote (https://x.com/Rob1Ham/status/2084523368783438198?s=20). “Funding is secured, I appreciate all the gestures for donations but it is not necessary. The bill is taken care of.”

According to Hamilton, the red team uses Kimi K3 alongside OpenAI’s GPT Sol, Anthropic’s Claude Fable and Opus models, and Z.ai’s GLM 5.2 to identify system vulnerabilities and generate the necessary supporting documentation.

“We also have been connected with OpenAI for some help so I could manage getting the Cyber Harness running as well,” he explained. “It's a much more expensive scan, but well worth it for load-bearing portions of the Bitcoin ecosystem and has already yielded good results.”

Pseudonymous Bitcoin developer Calle mentioned that the team has established multiple AI-driven review systems specifically targeting Bitcoin wallets, cryptographic libraries, core infrastructure, and various other projects.

"We're averaging on the order of one critical exploit per hour per person,” Calle reported on X (https://x.com/callebtc/status/2084561246305542617?s=20). “We've reported critical vulnerabilities to several projects in the last 12 hours. Thankfully, this is a very expensive exercise. We're burning through $10,000 per day."

The developers did not disclose the specific projects affected or provide deeper technical details regarding the vulnerabilities found, consistent with responsible disclosure practices that give maintainers time to patch issues before details become public.

The initiative's findings emerge as AI takes on an increasingly prominent role in uncovering security flaws throughout the crypto sector. Earlier this year, researchers employing Anthropic's Claude Opus 4.8 discovered a four-year-old vulnerability in Zcash that potentially allowed attackers to mint unlimited counterfeit ZEC. Furthermore, in August, Coinkite suggested that attackers used AI to pinpoint the Coldcard wallet vulnerability. Similarly, Bitcoin bridge Boltz temporarily suspended its swap service after noting that attackers were leveraging AI to discover vulnerabilities more rapidly than developers could issue patches. The pattern underscores a widening arms race in which the same AI capabilities are available to both attackers and defenders, making proactive security audits increasingly critical for open-source crypto projects.