Crypto

Bitcoin Red Team AI audit reports 4,962 findings across 390 projects

A volunteer group says AI-assisted reviews flagged hundreds of high-severity issues, but validation and patch outcomes remain unclear.

Dev Ramirez

By Dev Ramirez · Crypto Correspondent

· 3 min read

Bitcoin Red Team AI audit reports 4,962 findings across 390 projects
Photo: Decrypt

The Bitcoin Red Team AI audit has reported 4,962 findings across 390 Bitcoin-related projects after 27.5 hours of work. For people holding bitcoin or using Bitcoin software, the important distinction is that these are the group’s own security findings, not a public list of confirmed exploits or completed fixes.

In an Aug. 5 update on X, Bitcoin developer Calle said the 16-person volunteer group had labeled 85 findings critical and 635 high severity. The group said it was reviewing Bitcoin code bases and related open-source repositories. Its update did not identify the affected projects, and the available reporting does not establish that Bitcoin Core itself has a confirmed critical vulnerability.

Can an AI audit make Bitcoin software safer?

AI can search a large amount of code for suspicious patterns and possible attack paths faster than a small group can read it manually. That is a triage tool, meaning a way to prioritize what needs closer inspection. It does not, by itself, prove a bug can be exploited in real-world use.

Calle said the effort still involved substantial manual work: participants used different review methods and prompts while the group improved its automated testing harnesses. He said most critical reports were reproduced with proof-of-concept tests in local regtest environments before disclosure. A regtest environment is a private Bitcoin test network used to test software behavior without putting real funds at risk.

The group also said most of its critical reports had been quickly verified by project owners. But it has not published a project-by-project tally of those verifications, public advisories, patches, rejected reports or severity changes. That leaves outside readers unable to independently determine how many of the reported findings became confirmed, actionable vulnerabilities.

Coinpaper and Cointelegraph, writing through TradingView, each reported that 21.4% of all findings had been reproduced at the time of the update. That figure applies to the full pool of findings, not specifically to the critical category, and it is a reported campaign metric rather than an independent audit result.

A later campaign snapshot cited by egamers.io reported 6,700 findings across 425 projects after 55 hours, including 1,029 labeled high or critical. The earlier update listed critical and high categories separately, while the later one combined them, so the reports do not provide directly comparable severity breakdowns. Egamers.io also reported that the campaign had not released case-level outcomes, an aggregate false-positive rate or a fix rate.

The campaign followed reports of a Coldcard hardware-wallet incident, but the supplied evidence does not show that this audit discovered the Coldcard issue. The strongest conclusion so far is about speed: AI-assisted tools can generate a large queue of potential security work. Whether that work makes Bitcoin-related software safer depends on reproduction, maintainer acknowledgment, patches and public disclosures that allow the results to be checked.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto