Key highlights:

  • The Bitcoin Red Team has spotted 85 security vulnerabilities across nearly 400 Bitcoin projects
  • The team is leaning on AI to identify critical bugs in the projects, garnering broad ecosystem support
  • Projects are bolstering their defences after the jarring Coldcard wallet incident that rocked the Bitcoin community

Sixteen Bitcoin developers have identified 85 critical security bugs across 390 Bitcoin-related projects after using artificial intelligence to conduct a large-scale code audit. Dubbed the Bitcoin Red Team, the developers have uncovered 635 high-severity vulnerabilities and a total of 4,962 findings in under 24 hours.

AI accelerates Bitcoin security reviews but time is running out 

The Bitcoin Red Team, a volunteer initiative, targets Bitcoin wallets, cryptographic libraries and other infrastructure projects. Pseudonymous developer Calle described the situation as “extremely bad” as maintainers race to verify and fix reported flaws.

According to an X post, the developers estimate they are each discovering roughly one critical bug per hour while spending around $10,000 daily on computing resources. Although much of the review process still requires human oversight, the team said its AI-based testing systems will continue to improve.

Source: “callebtc” via X

Calle noted that affected teams have confirmed the authenticity of their findings, highlighting the importance of their frantic work. However, the flood of reports has created its own challenges with Calle noting that some maintainers have become overwhelmed by the volume of findings.

“We’ve been reaching out to many folks. Most of the critical reports we’ve made so far were quickly verified by project owners,” said Calle. “We know we are hitting real targets.”

Rob Hamilton, who is helping the Bitcoin Red Team’s automated review infrastructure noted that the primary challenge is no longer finding vulnerabilities but ensuring they reach the correct software maintainers quickly. He described the current effort as only the first version of what could become a far more effective security system.

The Bitcoin Red Team has received backing from the broader Bitcoin community. Calle confirmed that the team has received funding with donations converted to “AI tokens hunting for bugs in Bitcoin.”

Coldcard incidents triggers an ecosystem-wide race to secure Bitcoin

The Bitcoin Red Team’s audit follows recent security incidents within the Bitcoin ecosystem. Since July 30, attackers have exploited a firmware flaw in affected Coldcard wallets, sweeping as much as $114 million after taking advantage of a vulnerability that remained unnoticed since 2021.

The Coldcard security scare put the entire hardware wallet industry under pressure with BTC holders racing to secure their holdings. While several migrated their BTC to safe wallets, others are ditching the concept of self-custody altogether, turning towards spot Bitcoin ETFs for exposure.

Meanwhile, ecosystem players are wary of the incoming threat to Bitcoin by improvements in quantum computing. Strategy, Coinbase and other industry heavyweights have teamed up to create the Bitcoin Security Consortium, aiming to make the network resistant to future quantum-computing threats.

However, Jim Cramer plans to sell all his BTC after an interview with IBM CEO Arvind Krishna revealed the pace of quantum computing leaps. However, several pundits say the earliest quantum computing threat to Bitcoin is a decade away, giving time to developers to forge a secure future for the network.