← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] AI Finds 85 Critical Bitcoin Bugs in 27 Hours

Zephyra|August 7, 2026|BPF
EXECUTIVE SUMMARY

Sixteen volunteer Bitcoin developers, working under the banner "Bitcoin Red Team," filed 4,962 security findings across 390 open-source Bitcoin projects in 27.5 hours between August 4-5, 2026. Of those, 85 were classified critical and 635 high-severity. The operation, funded by $40,000 in AI comp...

"Open source is not a security property. It is a distribution and inspection property. Confusing the two is how the industry keeps selling trust minimization theater." — Charles Guillemet, CTO, Ledger

Executive Summary

Sixteen volunteer Bitcoin developers, working under the banner "Bitcoin Red Team," filed 4,962 security findings across 390 open-source Bitcoin projects in 27.5 hours between August 4-5, 2026. Of those, 85 were classified critical and 635 high-severity. The operation, funded by $40,000 in AI compute costs covered by OpenSats, deployed frontier AI models — including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2 — against wallets, cryptographic libraries, and infrastructure code. The team averaged one critical exploit per person per hour.

The sprint was triggered by the Coldcard hardware wallet exploit that began July 30, 2026, in which attackers leveraged a five-year-old firmware flaw to drain an estimated $116 million in Bitcoin from over 5,200 addresses. Coinkite, Coldcard's manufacturer, acknowledged the attacker likely used AI to identify the vulnerability in its open-source code. Days later, non-custodial swap protocol Boltz suspended operations indefinitely, citing AI-assisted automated probing that outpaced its team's ability to patch. The convergence of these events marks a structural shift in crypto security economics: AI has collapsed the cost of vulnerability discovery from six-figure audit contracts to under $50 per finding, and attackers and defenders now operate on the same accelerated timeline.

Table of Contents

  1. The Bitcoin Red Team: Anatomy of a 27.5-Hour Sprint
  2. The Coldcard Catalyst: $116M Stolen From a Five-Year-Old Bug
  3. Boltz Goes Dark: When AI Attacks Outpace Human Patches
  4. The Economics of AI-Powered Security
  5. Anthropic's Mythos and the Broader Vulnerability Landscape
  6. The Defender's Dilemma: Disclosure at Machine Speed
  7. Key Takeaways
  8. Conclusion

The Bitcoin Red Team: Anatomy of a 27.5-Hour Sprint

On August 4, 2026, Calle — the pseudonymous developer behind the Cashu ecash protocol — and Rob Hamilton, CEO of AnchorWatch, mobilized 16 developers distributed across time zones to run a coordinated offensive security review of the Bitcoin open-source ecosystem. The operation used AI models as force multipliers, scanning codebases at a rate no human team could match.

The numbers from the first 27.5 hours:

| Metric | Value | |---|---| | Total findings filed | 4,962 | | Critical severity | 85 | | High severity | 635 | | Projects scanned | 390 | | Filing rate | 166 findings/hour | | Findings with proof-of-concept code | ~21% | | False positives retired | 8 | | Average serious issues per project | 1.85 |

The vulnerability breakdown by category shows privacy and coinjoin tools carried the highest concentration of serious flaws at 24% high-or-critical, followed by swap and exchange protocols at 21%, payment and merchant tools at 17%, and cryptographic libraries and SDKs at 10%. The cryptographic library category, while lower in severity concentration, generated the largest absolute volume at 1,101 total findings — a function of the sheer codebase size in that segment.

The AI models deployed included Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, running at approximately $10,000 per day in compute costs. OpenSats, a 501(c)(3) nonprofit supporting open-source Bitcoin development, covered more than $40,000 in total AI compute expenses for the sprint.

As Hamilton put it: "The hardest part is coordinating to get things to the right people." Discovery is no longer the bottleneck. Verification, triage, and responsible disclosure routing have become the rate-limiting steps. As of publication, only 19 projects — under 5% — had received upstream disclosure, reflecting the sheer volume of findings relative to available coordination bandwidth.

The Coldcard Catalyst: $116M Stolen From a Five-Year-Old Bug

The Red Team sprint was a direct response to what became the largest hardware wallet exploit of 2026. Beginning July 30, attackers systematically drained Bitcoin from Coldcard hardware wallets by exploiting a flaw that had been dormant in public code since March 2021.

The vulnerability was a build configuration error in Coinkite's firmware. The device's seed generation was designed to use a hardware random number generator (TRNG) for entropy. Instead, a fallback condition caused certain firmware builds to default to a software-based pseudo-random number generator (PRNG), collapsing effective key strength from a designed 128 bits to as low as 40 bits on older devices. At 40-bit entropy, private keys become brute-forceable with commercially available computing power — no physical access to the device required.

According to Galaxy Research's running tally, as reported by CoinDesk on August 3, losses reached approximately 1,816 BTC (approximately $116 million at time of theft) across more than 5,200 addresses. The theft unfolded in at least four waves, with the first sweep moving roughly 594 BTC ($38 million) from approximately 500 wallets into a single consolidation address within 25 minutes.

Coinkite shipped emergency firmware on July 31, one day after the first thefts. The patch addresses the RNG fallback, but it cannot repair seeds already generated on vulnerable firmware versions. Users with affected devices must generate entirely new seeds on patched firmware and migrate funds — a manual process that leaves a window of exposure.

According to multiple reports, including Forbes, Coinkite acknowledged the attacker likely used AI to comb through its open-source code and identify the flaw. The bug had been in public repositories for five years. Every human reviewer and automated fuzzer that examined the code during that period missed it.

Boltz Goes Dark: When AI Attacks Outpace Human Patches

On August 5, Boltz — a non-custodial bridge for Bitcoin, Lightning Network, and Liquid transfers — suspended swap operations indefinitely. The team cited months of "AI-assisted automated probing" that had escalated beyond their capacity to respond.

Boltz's statement framed the situation as a paradigm shift: "Attackers are now iterating faster than a team of our size can find and fix." The protocol faced multiple well-resourced groups simultaneously, each deploying AI to discover and exploit vulnerabilities faster than the Boltz team could patch them.

Boltz emphasized that no user funds were at risk due to its non-custodial architecture. Losses were absorbed by the bootstrapped company itself. The API remains active for cooperative refunds, and unilateral refunds continue operating independently of Boltz infrastructure.

The Boltz shutdown illustrates a scenario that security researchers have warned about: AI-powered offense scaling faster than defense. A small open-source team with limited resources cannot match the throughput of AI-equipped attackers who can probe for new vulnerabilities continuously.

The Economics of AI-Powered Security

The Bitcoin Red Team's $40,000 audit budget produced 4,962 findings across 390 projects. That works out to approximately $8.06 per finding and $470 per critical vulnerability. By comparison, traditional manual security audits in 2026 cost between $50,000 and $500,000 per engagement and take 4-12 weeks to complete, according to industry estimates.

The cost asymmetry is stark:

| Parameter | Traditional Audit | Bitcoin Red Team (AI) | |---|---|---| | Cost per engagement | $50,000-$500,000 | $40,000 (390 projects) | | Time per engagement | 4-12 weeks | 27.5 hours | | Projects covered | 1 | 390 | | Cost per critical finding | $50,000+ (typical) | ~$470 | | Proof-of-concept rate | Varies | ~21% |

Anthropic's internal research provides another data point. The company's Mythos model, announced April 2026, discovered a 27-year-old denial-of-service vulnerability in OpenBSD's TCP SACK implementation — an integer overflow condition that allows a remote attacker to crash any OpenBSD host responding over TCP. The specific run that found the bug cost under $50 in compute. The broader scanning effort that included it ran approximately 1,000 scaffold iterations at a total cost under $20,000.

Coinbase's internal AI auditing system, Frosty, reportedly runs smart contract scans in one to two hours at up to 100x less than manual review costs, according to CoinDesk. Anthropic estimated the average cost of scanning a single smart contract for vulnerabilities at $1.22.

These figures suggest the economic moat around traditional security auditing is eroding rapidly. The question is whether the same cost collapse benefits attackers proportionally — and early evidence suggests it does.

Anthropic's Mythos and the Broader Vulnerability Landscape

The Bitcoin Red Team's operation exists within a broader shift in how software vulnerabilities are discovered. In April 2026, Anthropic announced Claude Mythos Preview, an AI model purpose-built for autonomous vulnerability discovery. Rather than releasing it publicly, Anthropic formed Project Glasswing — a coalition including AWS, Apple, Microsoft, Google, Cisco, CrowdStrike, NVIDIA, JPMorgan Chase, and Palo Alto Networks — to use Mythos in controlled environments.

Mythos's disclosed findings include:

  • A 27-year-old DoS vulnerability in OpenBSD's TCP SACK implementation (cost: under $50)
  • A 16-year-old vulnerability in FFmpeg's H.264 codec, introduced in a 2003 commit and exposed by a 2010 refactor
  • A 17-year-old remote code execution flaw (CVE-2026-4747) in the NFS server, granting unauthenticated root access, discovered and fully exploited autonomously

The Mythos findings extend well beyond cryptocurrency. But the crypto ecosystem's combination of open-source codebases, direct financial exposure, and pseudonymous attack surfaces makes it a primary testing ground for AI-powered exploitation.

According to Immunefi CEO Mitchell Amador, the crypto sector faces what he called a "vulnerability apocalypse," estimating defenders face "a 3-4 year recovery window before they can match the advantage that frontier AI models have given to attackers." Coinbase cut its critical bug bounty rewards 70% — from $50,000 to $15,000 — reportedly due to AI-generated vulnerability submission floods.

The Defender's Dilemma: Disclosure at Machine Speed

The Red Team's findings expose a coordination problem that scales poorly. Of 390 projects scanned, only 19 (under 5%) had received upstream disclosure by August 6. The remaining findings sit in a queue, each requiring verification, proof-of-concept reproduction, and routing to the correct maintainer — many of whom are solo developers or small volunteer teams.

This creates a race condition. The same AI capabilities available to the Red Team are available to attackers. Every day a critical finding sits undisclosed, the probability that an adversary independently discovers and exploits it increases. The Coldcard exploit demonstrated this concretely: a bug in public code for five years was found by an attacker, not a defender.

The Bitcoin Red Team plans to open-source its AI security harness, enabling other teams to run similar scans. The framework identifies critical libraries, reproduces vulnerabilities, packages evidence into structured reports, and supports responsible disclosure workflows. Whether open-sourcing the tooling helps defenders more than attackers remains an open question.

Ledger CTO Charles Guillemet, in a post on X responding to the Coldcard incident, drew a distinction that underpins the entire situation: "Open source is not a security property. It is a distribution and inspection property." He noted Ledger has spent two years using AI alongside human security engineers and cryptographers to proactively review code — a resource commitment unavailable to most Bitcoin open-source projects.

Key Takeaways

  • 4,962 findings in 27.5 hours. The Bitcoin Red Team's AI-assisted audit found 85 critical and 635 high-severity vulnerabilities across 390 Bitcoin projects, at a total cost of approximately $40,000 — funded by OpenSats.

  • $116 million stolen via a five-year-old bug. The Coldcard hardware wallet exploit, triggered by a firmware RNG fallback flaw dormant since March 2021, demonstrates that open-source code visibility does not equal security review.

  • AI has collapsed audit economics. The cost per critical finding dropped from $50,000+ (traditional audit) to approximately $470 (AI-assisted Red Team). Anthropic's Mythos found a 27-year-old bug for under $50 in compute.

  • Attackers and defenders now share the same tools. Boltz suspended operations after AI-assisted probing outpaced its patch cycle. Immunefi estimates defenders face a 3-4 year disadvantage window.

  • Disclosure is the new bottleneck. Under 5% of scanned projects received upstream disclosure. Verification and routing, not discovery, are the rate-limiting steps in coordinated vulnerability response.

  • The security subsidy gap is widening. Most Bitcoin open-source projects lack the resources to run continuous AI-powered security reviews. The $40,000 Red Team sprint covered 390 projects — a one-time effort that revealed the scale of unreviewed code across the ecosystem.

Conclusion

The Bitcoin Red Team's 27.5-hour sprint quantifies a problem the ecosystem has discussed abstractly for years: the gap between code availability and code review. At 1.85 serious issues per project across 390 repositories, the data suggests large portions of Bitcoin's open-source infrastructure have received inadequate security scrutiny.

AI has not created new vulnerability classes. What it has done is compress the discovery timeline from weeks to hours and the cost from six figures to three. This compression applies equally to attackers and defenders. The Coldcard exploit and the Boltz shutdown demonstrate the attacker side of this equation. The Red Team sprint demonstrates the defender side.

The structural challenge is economic. Traditional audit firms charge $50,000-$500,000 per engagement. Most Bitcoin open-source projects operate on volunteer labor and sporadic grants. OpenSats covered $40,000 for this sprint, but continuous AI-powered security monitoring at scale would require sustained funding mechanisms that do not currently exist for the long tail of Bitcoin infrastructure projects.

The Red Team's plan to open-source its AI security harness addresses the tooling gap but not the funding gap. Until the ecosystem develops sustainable economic models for ongoing security review — whether through protocol-level fee allocation, insurance mechanisms, or expanded grant programs — the disparity between code production velocity and code review velocity will continue to widen.

Sources & References

  1. Bitcoin Developers Flag 85 Critical Bugs in an "Extremely Bad" Situation — CoinDesk, August 6, 2026
  2. 'Situation Is Extremely Bad' — Bitcoin Braced For More 'Critical' Exploits After $10,000 Price Per Day AI Warning — Forbes, August 6, 2026
  3. Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit — Bitcoin Magazine, August 5, 2026
  4. Bitcoin AI Security Audit Files 4,962 Findings Across 390 Projects — Decrypt, August 6, 2026
  5. Boltz Halts Swaps: AI Attacks Outpace the Team — Atlas21, August 5, 2026
  6. The Largest Hardware Wallet Exploit of 2026: Inside the $116 Million Coldcard Hack — TRM Labs, August 2026
  7. Bitcoin Cold-Wallet Losses May Near $114 Million as Possible Fourth Sweep Emerges — CoinDesk, August 3, 2026
  8. AI-Assisted Bitcoin Red Team Flags 85 Critical Vulnerabilities — CoinTribune, August 6, 2026
  9. Coldcard Hack: $116 Million Bitcoin Stolen Via Firmware Flaw — Forbes, August 4, 2026
  10. Open Source Is Not a Security Property — Ledger Blog, August 2026
  11. AI Is Making Crypto Security Cheaper, Faster and Harder to Ignore — CoinDesk, June 20, 2026
  12. Bitcoin Red Team To Open Source AI Security Harness After Major Audit — Open Source For You, August 2026