Sixteen Bitcoin developers ran AI models against nearly 400 projects and found themselves buried in 4,962 security vulnerabilities before lunch the next day. Among them, 85 critical bugs and 635 high-severity issues. The sheer volume is now creating its own chaos across the ecosystem.
The coordinated audit pointed AI at Bitcoin wallets, cryptographic libraries, and infrastructure code. Running automated security checks costs about $10,000 daily in compute, yet the payoff is staggering, one critical flaw discovered roughly every hour per person involved. Calle, the pseudonymous developer behind the Cashu ecash protocol, called the situation "extremely bad" and acknowledged the group is still learning to filter signal from noise.
Most critical findings have been quickly verified by project owners and come with working proof of concepts tested locally before release. But maintainers are drowning. "There's a lot of chaos right now in the ecosystem," Calle wrote, apologizing to teams now buried under report backlogs. The group publishes fast because maintainers can verify findings almost for free using identical tools, and because others outside the red team will eventually discover the same bugs anyway.
What's shifted here is speed and scale. AI has weaponized security research for both defenders and attackers simultaneously. The bottleneck isn't finding vulnerabilities anymore, it's triaging and patching them before malicious actors weaponize the same discoveries. Rob Hamilton, building the automated harness powering the audit, flagged this exact problem in recent posts. The ecosystem now faces a race between disclosure and exploitation that traditional manual audits never compressed into such tight timeframes.
This material is informational and does not constitute financial or investment advice. Always conduct your own research and consult with qualified professionals before making decisions regarding cryptocurrency or security matters.


