toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
To be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

Volunteer developers use AI to audit Bitcoin projects

2026-08-07 12:10

A volunteer team of Bitcoin developers says it found 4,962 potential security flaws across roughly 390 Bitcoin-related projects in a 24-hour AI-assisted audit, including 85 rated critical and 635 rated high risk. The campaign, conducted by 16 volunteers working rotating shifts, has added urgency to security reviews after a reported Coldcard hardware-wallet exploit that exposed thousands of bitcoin addresses and led users to move funds from potentially affected devices.

The group said most findings from the code sweep were confirmed by the affected projects. Its results were aggregated across wallets, libraries, infrastructure tools and other software used around the Bitcoin ecosystem, rather than representing vulnerabilities in Bitcoin’s base protocol itself.

The speed of the exercise is likely to sharpen a difficult security question for open-source projects: the same advanced models that can help small development teams identify defects at scale could also lower the cost for attackers searching for weak cryptographic implementations, exposed keys or unsafe wallet code.

The volunteers used Moonshot’s Kimi K3 model and estimated daily computing costs at about $10,000, funded by OpenSats. With the team operating across time zones, the audit’s reported pace worked out to about one critical finding per hour.

Coldcard incident drives fresh attention to wallet security

The scan followed reports of an exploit involving Coldcard hardware wallets, in which roughly 2,000 bitcoin, valued at just over $100 million at the time described in the report, were taken over several days. The reported theft was linked to a key-generation flaw that had allegedly remained in affected code for five years.

The incident illustrates the risk of weaknesses that occur before a Bitcoin transaction is ever signed or broadcast. Hardware wallets are designed to keep private keys offline, but their protection depends on the randomness used to generate those keys and the recovery seed phrases backing them up. If an attacker can predict or reconstruct a weakly generated seed, the device itself does not need to be physically compromised.

Coldcard told users to treat the situation as urgent and issued model-specific guidance that included upgrading devices, creating a new seed phrase and transferring holdings to newly generated wallets. The company said the threat was ongoing when it published its notices.

Creating a new seed is central to that advice. Updating device software may prevent a known defect from affecting future key generation, but it cannot change keys or recovery phrases that were already produced using a vulnerable process. Funds controlled by an exposed seed need to be transferred to an address secured by a newly created one.

Reports linked the affected funds to more than 5,200 Bitcoin addresses. One address associated with the attacker was said to retain about $36 million in bitcoin, much of it believed to be stolen. The address also received further inbound transfers after the incident became public, including transactions containing messages through Bitcoin’s OP_RETURN function.

OP_RETURN allows users to attach small pieces of data to a Bitcoin transaction. Messages sent to the address reportedly included appeals for the return of stolen bitcoin and one offer of laundering services that said: “I wash BTC, do KYC and cash out. I take 10%.”

AI changes the economics of code review

The developers’ campaign offers a practical demonstration of where AI can fit into Bitcoin security work. Open-source projects often face a mismatch between the amount of code that needs to be reviewed and the number of experienced auditors available to inspect it. Automated tools can rapidly flag suspicious patterns, such as unsafe handling of random number generation, missing validation checks, or code paths that could expose secrets.

A model-generated finding is not automatically a vulnerability. It must be reviewed, reproduced and assessed by maintainers or security specialists before a project can determine its severity and fix. The group’s statement that most findings were confirmed by affected projects is therefore more consequential than the raw number of alerts, although the severity ratings remain tied to the audit team’s classification process.

The large number of reported issues also should not be read as evidence that Bitcoin’s underlying blockchain is suddenly compromised. The sweep covered a wide surrounding ecosystem, where code quality and maintenance standards vary considerably. Wallet software, developer libraries and hardware integrations can each create security failures without altering Bitcoin’s consensus rules.

Cobra, the anonymous co-owner of Bitcoin.org, was cited in the report as raising concerns that AI may have played a role in the Coldcard theft. No public evidence described in the material establishes how the attacker identified or exploited the reported vulnerability. Yet the combination of a long-lived wallet flaw and increasingly accessible automated code-analysis tools gives defenders less time to discover and patch defects.

Security response extends beyond a firmware update

For Coldcard users, the immediate issue is whether their device model and seed-generation process fall within the company’s affected guidance. Owners who believe their wallets may be exposed have been urged to follow Coldcard’s instructions for their specific device, generate a fresh seed in a safe environment and move funds promptly.

The incident also places renewed focus on the distinction between holding bitcoin personally and managing the security process personally. Self-custody removes reliance on an intermediary but leaves users responsible for verifying wallet setup, device authenticity, backup practices and recovery procedures.

The volunteer audit is continuing across the Bitcoin software ecosystem. Its early results suggest that AI-assisted review can give maintainers a faster way to locate weak points that might otherwise sit unnoticed for years, while also making prompt patching and careful disclosure more pressing once a flaw is found.


Worried about wallet exploits? Strengthen your defenses with practical tips from this crypto wallet security guide now.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.