A Bitcoin security resource group said it used frontier artificial intelligence (AI) models to inspect about 150 Bitcoin-related repositories, found more than 12 vulnerabilities and notified each project.
On Aug. 8 local time, blockchain outlet Decrypt reported that the group is conducting AI-based security audits across key Bitcoin software, including wallets, cryptographic libraries and infrastructure.
The effort is part of building a so-called "Bitcoin red team" platform. A red team refers to security personnel who test software from an attacker’s perspective to find vulnerabilities before real-world exploitation. The group is also developing an open-source AI platform for auditing Bitcoin software.
Rob Hamilton (롭 해밀턴), chief executive of AnchorWatch, said in a post on X, formerly Twitter, last week that he has spent about $20,000 so far on several AI services. "Thanks for the donation offers, but they are not needed. The costs are already covered," he said.
Hamilton said the group is using Kimi K3, OpenAI’s GPT Sol, Anthropic’s Claude Fable and Opus, and Z.ai’s GLM 5.2 to identify vulnerabilities and draft related documentation. He said the group also worked with OpenAI and received support to run "Cyber Harness". "It was a much more expensive effort, but it was worth it and it has already produced good results," he said.
A pseudonymous developer, Kalle (칼레), explained that the group has built multiple AI review systems targeting wallets, cryptographic libraries, infrastructure and other Bitcoin projects. "On average, it finds about 1 vulnerability per hour," Kalle said, adding that it reported critical vulnerabilities to several projects over the past 12 hours. "Fortunately, it is expensive and we are burning $10,000 a day," Kalle added.
The group did not disclose which projects were affected or the specifics of the vulnerabilities. It appeared to be following the practice of delaying detailed disclosures for security issues that could be exploited, but the group did not provide targets or technical details in its announcement.
The announcement comes as the use of AI for security checks is rising quickly in the cryptocurrency industry. Earlier this year, researchers using Anthropic’s Claude Opus 4.8 found a flaw that had existed in Zcash for 4 years, and the vulnerability was linked to the possibility that an attacker could generate unlimited counterfeit ZEC. In August, CoinKite said it is seeing reports that attackers used AI to identify vulnerabilities in Coldcard wallets, and Bitcoin bridge Boltz suspended its swap service, saying attackers are finding vulnerabilities with AI faster than its team can patch them.
AI is emerging in the Bitcoin development ecosystem both as a defensive tool and as a means to accelerate attacks. The Bitcoin red team’s work is an example of expanding proactive checks across core repositories, and the next focus is expected to be the scope of actual vulnerability disclosures and whether the open-source audit platform will be released.