🔥BTC/USDT

Volunteer developers use AI to audit Bitcoin projects

A volunteer team of Bitcoin developers says it found 4,962 potential security flaws across roughly 390 Bitcoin-related projects in a 24-hour AI-assisted audit, including 85 rated critical and 635 rated high risk. The campaign, conducted by 16 volunteers working rotating shifts, has added urgency to security reviews after a reported Coldcard hardware-wallet exploit that exposed thousands of bitcoin addresses and led users to move funds from potentially affected devices.

The group said most findings from the code sweep were confirmed by the affected projects. Its results were aggregated across wallets, libraries, infrastructure tools and other software used around the Bitcoin ecosystem, rather than representing vulnerabilities in Bitcoin’s base protocol itself.

The speed of the exercise is likely to sharpen a difficult security question for open-source projects: the same advanced models that can help small development teams identify defects at scale could also lower the cost for attackers searching for weak cryptographic implementations, exposed keys or unsafe wallet code.

The volunteers used Moonshot’s Kimi K3 model and estimated daily computing costs at about $10,000, funded by OpenSats. With the team operating across time zones, the audit’s reported pace worked out to about one critical finding per hour.

Coldcard incident drives fresh attention to wallet security

The scan followed reports of an exploit involving Coldcard hardware wallets, in which roughly 2,000 bitcoin, valued at just over $100 million at the time described in the report, were taken over several days. The reported theft was linked to a key-generation flaw that had allegedly remained in affected code for five years.

The incident illustrates the risk of weaknesses that occur before a Bitcoin transaction is ever signed or broadcast. Hardware wallets are designed to keep private keys offline, but their protection depends on the randomness used to generate those keys and the recovery seed phrases backing them up. If an attacker can predict or reconstruct a weakly generated seed, the device itself does not need to be physically compromised.

Coldcard told users to treat the situation as urgent and issued model-specific guidance that included upgrading devices, creating a new seed phrase and transferring holdings to newly generated wallets. The company said the threat was ongoing when it published its notices.

Creating a new seed is central to that advice. Updating device software may prevent a known defect from affecting future key generation, but it cannot change keys or recovery phrases that were already produced using a vulnerable process. Funds controlled by an exposed seed need to be transferred to an address secured by a newly created one.

Reports linked the affected funds to more than 5,200 Bitcoin addresses. One address associated with the attacker was said to retain about $36 million in bitcoin, much of it believed to be stolen. The address also received further inbound transfers after the incident became public, including transactions containing messages through Bitcoin’s OP_RETURN function.

OP_RETURN allows users to attach small pieces of data to a Bitcoin transaction. Messages sent to the address reportedly included appeals for the return of stolen bitcoin and one offer of laundering services that said: “I wash BTC, do KYC and cash out. I take 10%.”

AI changes the economics of code review

The developers’ campaign offers a practical demonstration of where AI can fit into Bitcoin security work. Open-source projects often face a mismatch between the amount of code that needs to be reviewed and the number of experienced auditors available to inspect it. Automated tools can rapidly flag suspicious patterns, such as unsafe handling of random number generation, missing validation checks, or code paths that could expose secrets.

A model-generated finding is not automatically a vulnerability. It must be reviewed, reproduced and assessed by maintainers or security specialists before a project can determine its severity and fix. The group’s statement that most findings were confirmed by affected projects is therefore more consequential than the raw number of alerts, although the severity ratings remain tied to the audit team’s classification process.

The large number of reported issues also should not be read as evidence that Bitcoin’s underlying blockchain is suddenly compromised. The sweep covered a wide surrounding ecosystem, where code quality and maintenance standards vary considerably. Wallet software, developer libraries and hardware integrations can each create security failures without altering Bitcoin’s consensus rules.

Cobra, the anonymous co-owner of Bitcoin.org, was cited in the report as raising concerns that AI may have played a role in the Coldcard theft. No public evidence described in the material establishes how the attacker identified or exploited the reported vulnerability. Yet the combination of a long-lived wallet flaw and increasingly accessible automated code-analysis tools gives defenders less time to discover and patch defects.

Security response extends beyond a firmware update

For Coldcard users, the immediate issue is whether their device model and seed-generation process fall within the company’s affected guidance. Owners who believe their wallets may be exposed have been urged to follow Coldcard’s instructions for their specific device, generate a fresh seed in a safe environment and move funds promptly.

The incident also places renewed focus on the distinction between holding bitcoin personally and managing the security process personally. Self-custody removes reliance on an intermediary but leaves users responsible for verifying wallet setup, device authenticity, backup practices and recovery procedures.

The volunteer audit is continuing across the Bitcoin software ecosystem. Its early results suggest that AI-assisted review can give maintainers a faster way to locate weak points that might otherwise sit unnoticed for years, while also making prompt patching and careful disclosure more pressing once a flaw is found.


Worried about wallet exploits? Strengthen your defenses with practical tips from this crypto wallet security guide now.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

Sign up and trade to earn over 15,000 USDT
Sign up