Bitcoin 'Red Team' Says AI Is Finding 100s Of Critical Exploits Across Core Projects
Read this article in:A volunteer security initiative says it has used frontier AI models to scan 150 Bitcoin repositories, uncovering more than a dozen vulnerabilities as developers increasingly turn to artificial intelligence to audit blockchain software.
In a post on X earlier this week, AnchorWatch CEO Rob Hamilton said the group has spent roughly $20,000 on AI services while developing a “Bitcoin red team” platform.
“We have been working around the clock, with ~$20,000 of spend up to this point across different services,” Hamilton wrote.
“Funding is secured. I appreciate all the gestures for donations, but it is not necessary. The bill is taken care of.”
In cybersecurity, a red team is a group that tests software from an attacker’s perspective, actively probing systems for vulnerabilities before they can be exploited.
Hamilton said the Bitcoin red team uses Kimi K3 alongside OpenAI’s GPT Sol, Anthropic’s Claude Fable and Opus models, and Z.ai’s GLM 5.2 to identify vulnerabilities and produce supporting documentation.
“We also have been connected with OpenAI for some help so I could manage getting the Cyber Harness running as well,” he wrote.
“It's a much more expensive scan, but well worth it for load-bearing portions of the Bitcoin ecosystem and has already yielded good results.”
Pseudonymous Bitcoin developer Calle said the initiative has built multiple AI-powered review systems targeting wallets, cryptographic libraries, infrastructure, and other Bitcoin projects.
“We're averaging on the order of one critical exploit per hour per person,” Calle wrote on X.
“We've reported critical vulnerabilities to several projects in the last 12 hours. Thankfully, this is a very expensive exercise. We're burning through $10,000 per day.”
According to Calle, the team identified 4,962 potential issues across 390 projects during its first 29.8 hours of operation.
Of those findings, as many as 720 were classified as high- or critical-level issues. So far, 21.4% of the findings have been successfully reproduced.
The team has not disclosed which projects were affected or provided details about the vulnerabilities.
The announcement comes as AI plays an increasingly prominent role in identifying security flaws across the cryptocurrency industry.
Earlier this year, researchers using Anthropic’s Claude Opus 4.8 uncovered a four-year-old vulnerability in Zcash that could have allowed attackers to create unlimited counterfeit ZEC. In August, Coinkite said it believed attackers had used AI to identify a vulnerability in its Coldcard wallet. Bitcoin bridge Boltz also suspended its swap service after saying attackers were using AI to identify vulnerabilities faster than its team could patch them.
comments
Please login to post comments: