Key Takeaways
AI-assisted security audits are helping researchers uncover critical vulnerabilities across Bitcoin projects before attackers can exploit them.
The Bitcoin Red Team combines AI tools with human expertise to responsibly disclose flaws and strengthen the ecosystem.
The initiative highlights both the growing role of AI in cybersecurity and the need for proactive code reviews to prevent costly exploits.
Bitcoin Security Researchers Turn to AI
A volunteer group of Bitcoin security researchers says it has found many serious software vulnerabilities after using artificial intelligence to scan wallets, cryptographic libraries, and other important Bitcoin projects.
The group, called the Bitcoin Red Team, says it has reviewed hundreds of software repositories, privately reported security problems to developers, and spent tens of thousands of dollars on AI tools to help make the Bitcoin ecosystem safer before hackers can take advantage of hidden flaws.
AnchorWatch CEO Rob Hamilton, who is helping lead the project, said the team first scanned 150 Bitcoin-related repositories and privately reported more than a dozen vulnerabilities. He said the group had spent about $20,000 on AI services during the early stage of the project.
"We have done over a dozen disclosures up to this point, with 150 repos scanned," Hamilton wrote on X, adding that "the hardest part is coordinating to get things to the right people."
The researchers are using an AI system called "red team agent harness" that automatically checks software for security problems. Hamilton said the system uses Kimi K3 to do most of the code analysis, while other AI models help write reports explaining the findings.
Hamilton said the tool is still in its early stages, but it has already found critical security issues. He added, "Our goal is to open source the harness so it can be pointed at internal repositories for insights so the hardening of defenses can go deeper than the code which is made public."
The team has also received help from OpenAI to use its Cyber Harness security system. Hamilton said those scans cost more money, but "well worth it for load bearing portions of the bitcoin ecosystem" because they have already produced useful results.
The project launched after attackers exploited a flaw in Coinkite's Coldcard Mk3 hardware wallet. The bug reportedly allowed hackers to steal more than 1,300 bitcoin, worth about $90 million at the time, from numerous wallets.
Hamilton, who has been involved in efforts to minimize the damage, shared an urgent warning on X during the early stages of the attack. "The attackers are sweeping any and all balances they find," he wrote. "YOU STILL HAVE TIME GET YOUR BITCOIN OFF COLD CARDS DO NOT WAIT EVERY SECOND COUNTS."
The attack showed how expensive software bugs can become when they are not discovered early. The Bitcoin Red Team hopes to find these kinds of problems before criminals can use them.
Bitcoin developer CalleBTC, who is also part of the project, said the team is finding serious security problems much faster than expected.
"(The) situation is extremely bad," CalleBTC wrote on X. "We're averaging on the order of 1 critical exploit per hour per person."
CalleBTC also said the researchers had reported critical vulnerabilities to several projects in just 12 hours. He added that the work costs around $10,000 each day in AI computing, with OpenSats paying the bills and Moonshot AI providing access to its Kimi K3 model.
As the project continued to grow, Hamilton said the team had expanded its work. In a later update, he said the researchers had scanned more than 300 repositories while total spending had increased to nearly $40,000.
"We are accelerating," Hamilton wrote. "Not only in the expanse of repositories covered (over 300) and our spend (almost $40k), but in the efficiency to quickly identify where parts of the codebases will break."
Hamilton said the project has also shown that experienced security researchers are still very important. He explained that AI often detects signs of a problem, but human experts can give the system a little extra guidance that helps it uncover much more serious vulnerabilities.
"It's almost like the agent can smell out something is wrong, but hasn't been trained enough yet to clearly verbalize it," Hamilton wrote.
The team is now working to improve both its AI tools and the way it reports vulnerabilities to developers. Hamilton said the biggest challenge is making the reporting process faster and easier.
In the latest development, CalleBTC shared an update on the Bitcoin Red Team. He said now a 16-person global security team is conducting a large-scale audit of Bitcoin-related codebases.

CalleBTC on X
After 27.5 hours, the team reported nearly 5,000 findings across 390 projects, including 85 critical and 635 high-severity issues, highlighting the scale of ongoing security reviews.





