AI-assisted security audit of 390 Bitcoin ecosystem projects uncovered nearly 5,000 software issues, including 85 critical and 635 high-severity vulnerabilities, in 30 hours.
AI & Agents ·
A coordinated security initiative examining 390 Bitcoin-related projects identified nearly 5,000 software issues in roughly 30 hours, combining human review with artificial intelligence tools. The effort, led by 16 security researchers and backed by OpenSats, OpenCode, and AI inference sponsors, uncovered 85 critical and 635 high-severity vulnerabilities across the projects, with researchers reporting an average of 166 findings per hour. The campaign differed from a traditional security audit in that human reviewers actively guided AI systems throughout testing, with each participant employing distinct prompts and methods to surface weaknesses a single approach might miss.
The findings revealed that approximately one in seven reported issues fell into high or critical severity categories, with crypto libraries and software development kits accounting for the largest share at 1,385 reported issues. Only one reviewed project emerged without any reported findings. Researchers have begun notifying affected project maintainers of verified critical findings and providing proof-of-concept retest demonstrations; many maintainers reportedly confirmed reports quickly, though managing the large volume remains challenging.
The initiative underscores growing focus on Bitcoin software security, though questions remain about how maintainers will prioritize and remediate such a substantial backlog and whether follow-up audits will track actual patch rates across the ecosystem.