Home
/
Crypto assets
/
Bitcoin
/

Ai supported volunteers uncover major bitcoin code vulnerabilities

Major Vulnerabilities Identified in Bitcoin Code | 85 Critical Bugs Found

By

Peter McCormack

Aug 26, 2026, 12:27 PM

Updated

Aug 27, 2026, 12:27 AM

2 minutes reading time

A group of volunteers using laptops to analyze Bitcoin code, with a digital representation of the Bitcoin logo and code snippets in the background.

A recent initiative involving 16 global volunteers has exposed 85 critical vulnerabilities in Bitcoin's code, occurring shortly after the Coldcard hack. The effort was driven by rising security concerns, with losses surpassing $100 million following the incident.

Who's Behind the Findings?

Led by developer Calle and AnchorWatch CEO Rob Hamilton, the Bitcoin Red Team harnessed advanced AI models to analyze Bitcoin's open-source repositories. Funded by OpenSats at approximately $10,000 a day, the team completed a 27.5-hour sprint beginning August 4, resulting in significant findings across various Bitcoin projects.

Key Discoveries and Exploits

The Red Team uncovered a staggering 4,962 total findings across 390 projects, marking this as a crucial response amidst heightened security threats. 635 of these were classified as high severity, with project owners validating most reports. Despite the detection of these vulnerabilities, verification and routing became significant bottlenecks, as less than 5% of projects had reached formal disclosure.

"The bottleneck isnโ€™t discovery anymore; itโ€™s verification and routing," noted team members addressing concerns about the process.

In a grim twist, during the same timeframe, a critical vulnerability in BTCPay Server was exploited, leading to the draining of Lightning nodes. Attackers reportedly accessed macaroon credential files, impacting multiple operations, including a hardware wallet company known as Foundation. These critical vulnerabilities had been previously reported to BTCPay by Red Team members.

Community Reactions and Remarks

Mixed sentiments have emerged from the crypto community regarding the efficacy of self-hosted systems. Some voices in forums expressed concerns, stating, "Why not use an exchange or Bitcoin Core at this point?" Others noted the critical nature of maintaining strong protocols when managing self-hosted setups.

Additionally, the results have sparked debates on AI tools in security. Some participants remarked, "This was written by AI. Interesting nonetheless," emphasizing the importance of human oversight in the process.

Themes Emerging from the Comments

  • Self-Hosting Concerns: Users question the reliability of systems like BTCPay.

  • AI's Role: There's debate around how beneficial AI is in identifying vulnerabilities.

  • Community Trust: The mixed feedback indicates a lack of consensus on the response effectiveness.

Takeaways

  • โ–ณ 85 critical vulnerabilities identified across Bitcoin projects

  • โ–ฝ Less than 5% of findings reached formal disclosure at the 30-hour mark

  • โ€ป "The bottleneck isnโ€™t discovery anymore" - Bitcoin Red Team member

The implications of these findings are far-reaching. With threats evolving rapidly, the crypto community must adapt and enhance its security protocols, or risk further breaches. Major projects may increasingly reassess their strategies in light of these revelations.