📈 Get daily crypto insights that make you smarter about your money

AI Scans Find 85 Critical Bugs in Bitcoin Infrastructure in Just One Day — and Attackers Are Already Exploiting Them

A volunteer team of sixteen Bitcoin developers has used AI tools to uncover nearly 5,000 security vulnerabilities across 390 cryptocurrency projects in just 24 hours — including 85 rated critical — exposing what one participant called an “extremely bad” situation that could affect everything from wallets to Lightning network nodes.

By Amir Hassan | August 10, 2026

The Architecture

The audit, organized by a group calling itself the Bitcoin Red Team, deployed AI models against the source code of hundreds of Bitcoin-related projects simultaneously. The approach was both simple and alarming: take proven AI code-analysis tools, point them at open-source repositories, and see what breaks.

The results were staggering. According to Calle, the pseudonymous developer behind the Cashu ecash protocol who announced the findings, the team filed 4,962 vulnerability reports in roughly 24 hours. Of those, 85 were classified as critical — meaning they could allow attackers to steal funds, compromise private keys, or take over infrastructure — and 635 were rated high severity.

Think of it like sending a thousand home inspectors into a neighborhood with thermal cameras and structural analysis tools. Except in this case, the “homes” are the software programs that collectively handle billions of dollars in cryptocurrency, and the “inspectors” are AI models that never sleep and cost roughly ten thousand dollars a day in compute to run.

Consensus Mechanisms

The audit was not centrally planned. Instead, it followed a decentralized model familiar to anyone in the crypto world. Each of the sixteen developers chose their own preferred AI tools and review methods, then targeted different repositories. The team used automated “harnesses” — software pipelines that feed code to AI models and collect the results — built by Rob Hamilton, a developer who has been pioneering this approach.

Hamilton noted that the hardest part was not finding bugs but routing them to the right maintainers. With 4,962 findings spread across 390 projects, coordination became the bottleneck. The team published findings quickly because, as Calle explained, “others who aren’t on the red team will arrive at the same findings as we did.” In other words, if the good guys found these bugs using AI, the bad guys could too — and probably already have.

This prediction was validated almost immediately. Just days after the audit began, a critical vulnerability in BTCPay Server — the popular open-source payment processor used by merchants to accept Bitcoin — was actively exploited by attackers who drained Lightning network nodes. The BTCPay team confirmed that the flaw had already been reported by Red Team members, but attackers moved before all servers could be patched.

Network Health

The findings paint a troubling picture of Bitcoin infrastructure security. Many of the vulnerabilities were in projects that handle real money — wallets, payment processors, Lightning network implementations, and cryptographic libraries. The Coldcard hardware wallet breach, which began in late July and reportedly resulted in significant losses, was traced to a bug that had been dormant since 2021.

What makes this particularly concerning is the asymmetry between attackers and defenders. Calle noted that the group is “averaging roughly one critical bug per hour per person” — a pace that no human security team can match. AI tools can scan codebases in minutes that would take human auditors weeks. The cost of running these scans is modest compared to the potential damage: the group estimated compute costs at approximately ten thousand dollars per day, a trivial sum for well-funded attackers.

The broader context is even more unsettling. Anthropic, one of the leading AI companies, disclosed in April that one of its models found a bug that had gone undetected for 27 years in widely used encryption software — at a cost of less than fifty dollars. Google’s threat intelligence team reported in May that criminal groups are already building AI-driven attack tools based on discovered vulnerabilities.

Developer Ecosystem

The audit has created a secondary crisis: maintainers of open-source crypto projects are now overwhelmed. With 4,962 findings landing in their issue trackers in a single day, many lack the resources to verify, prioritize, and fix the reports fast enough. Calle acknowledged the problem, writing that “there’s a lot of chaos right now in the ecosystem” and apologizing to maintainers “buried in reports.”

This highlights a structural weakness in crypto infrastructure: much of the critical software that handles Bitcoin and other cryptocurrencies is maintained by small teams or individual volunteers. When AI-powered audits surface hundreds of critical bugs simultaneously, the fix queue becomes a race against attackers who may already be exploiting the same flaws.

The BTCPay exploit demonstrated this race in real time. The Red Team had responsibly disclosed the vulnerability, but BTCPay’s public warning went out while attackers were already actively exploiting it against live servers. Among the confirmed victims were Foundation, a hardware wallet maker whose Lightning node was drained overnight, and Citadel21, a Bitcoin publication whose node was also swept.

Final Assessment

For users and investors, the implications are clear. The software securing cryptocurrency is not as battle-tested as the community has long believed. AI tools have revealed that years of human auditing missed thousands of vulnerabilities, and the window between discovery and exploitation is shrinking rapidly.

Practical takeaways for anyone holding crypto: update your wallet software immediately when patches are released, use hardware wallets from reputable manufacturers (and check whether they have been affected by recent audits), avoid keeping significant funds on Lightning nodes that have not been recently updated, and pay attention to security advisories from the projects you rely on.

The Bitcoin Red Team’s audit may turn out to be a watershed moment for crypto security — the moment when AI went from being a novelty to a weapon that both sides wield. The question now is whether the ecosystem can patch faster than attackers can exploit. Based on the early evidence, that race is going to be close.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

2 thoughts on “AI Scans Find 85 Critical Bugs in Bitcoin Infrastructure in Just One Day — and Attackers Are Already Exploiting Them”

  1. 85 critical bugs in 24 hours across 390 projects. and these are just the ones an AI scanner found. imagine what nation state teams already know.

  2. the fact that nobody is talking about how many of these 85 criticals are supposedly already being exploited tells you everything about this space. security is an afterthought until funds disappear

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,091.00-1.7%ETH$1,874.69-2.5%SOL$75.87-1.8%BNB$601.66-1.1%XRP$1.02-2.1%ADA$0.1956-1.1%DOGE$0.0697-1.3%DOT$0.8040-0.8%AVAX$6.46-1.2%LINK$8.27-0.8%UNI$3.94-2.6%ATOM$1.42+2.2%LTC$45.26-2.4%ARB$0.0802+2.4%NEAR$1.62-0.4%FIL$0.6980-1.8%SUI$0.6893-2.0%BTC$64,091.00-1.7%ETH$1,874.69-2.5%SOL$75.87-1.8%BNB$601.66-1.1%XRP$1.02-2.1%ADA$0.1956-1.1%DOGE$0.0697-1.3%DOT$0.8040-0.8%AVAX$6.46-1.2%LINK$8.27-0.8%UNI$3.94-2.6%ATOM$1.42+2.2%LTC$45.26-2.4%ARB$0.0802+2.4%NEAR$1.62-0.4%FIL$0.6980-1.8%SUI$0.6893-2.0%
Scroll to Top