Home Content News Bitcoin Red Team To Open Source AI Security Harness After Major Audit

Bitcoin Red Team To Open Source AI Security Harness After Major Audit

0
1
Image for representation purpose
Image for representation purpose

An AI-powered Bitcoin Red Team has uncovered 85 critical vulnerabilities across more than 390 open-source repositories after the Coldcard exploit, with plans to open source its security harness to strengthen ecosystem-wide defence.

An AI-powered Bitcoin Red Team has uncovered 4,962 security findings, including 85 critical and 635 high-severity vulnerabilities, after auditing more than 390 open-source Bitcoin repositories in the wake of the Coldcard hardware wallet exploit that resulted in losses exceeding US$100 million.

Led by Calle, software engineer and creator of the Android version of Bitchat, and Rob Hamilton, CEO of Anchorwatch, the initiative has spent more than US$40,000 on AI compute. Funding has come from OpenSats, the non-profit organisation supporting open-source Bitcoin development.

The team plans to open source its custom AI security harness, enabling Bitcoin companies to test even their closed-source software. The framework identifies critical libraries, reproduces vulnerabilities, packages evidence into reports and supports responsible disclosure to developers. Critical issues are already being reported privately to affected open-source projects.

The security review uses frontier AI models including Kimi K3, GPT Sol, Fable, Opus and GLM5.2. The project initially relied heavily on Chinese open-source AI models before gaining access to OpenAI and Anthropic models as the initiative expanded.

Providing an update on the effort, Calle said, “27.5 hours in, we’ve filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We’re at 2.31 h+c findings per person per hour.”

Hamilton highlighted the continuing role of human expertise alongside AI, noting that engineers “…might otherwise ‘smell out something is wrong,’ but might be missing niche context.” The initiative demonstrates how AI-assisted auditing and responsible disclosure can strengthen the security of critical open-source infrastructure.

LEAVE A REPLY

Please enter your comment!
Please enter your name here