AI Bitcoin Security Campaign Finds Nearly 5,000 Software Issues in 390 Projects
A coordinated campaign of 16 security researchers using AI tools identified nearly 5,000 software vulnerabilities across 390 Bitcoin projects in just 30 hours, uncovering 85 critical issues that institutional investors rely on for custody, trading, and infrastructure. The findings expose systemic weaknesses in open-source Bitcoin libraries and SDKs at a moment when ecosystem security has become a competitive differentiator for institutional adoption.
- 4,962 total findings across 390 Bitcoin projects, including 85 critical and 635 high-severity issues discovered in 30 hours
- 1,385 reported issues concentrated in crypto libraries and software development kits, the largest category of affected software
- Campaign averaged 166 findings per hour using human-guided AI, yielding 2.3 critical or high-severity issues per person-hour spent
- 4,962 total software findings across 390 Bitcoin projects in one coordinated campaign
- 85 critical-severity issues identified, representing systemic risk across infrastructure layer
- 30 hours timeframe for discovering vulnerabilities versus traditional multi-month security audits
A rapid security review organized by developer Calle and supported by OpenSats, OpenCode, and AI inference sponsors uncovered nearly 5,000 software defects across hundreds of Bitcoin-related projects between July 30 and July 31.
The 16-person research team combined manual code review with artificial intelligence tools to systematically examine 390 open-source projects, yielding 4,962 reported findings in approximately 30 hours of coordinated work.
The scale and speed of the campaign distinguish it from traditional security audits conducted over months by small teams, exposing the potential for AI-assisted vulnerability discovery to accelerate threat identification across decentralized ecosystems.
Crypto Libraries Account for Nearly 1,400 of 4,962 Total Findings
The highest concentration of reported issues appeared in crypto libraries and software development kits, which recorded 1,385 findings, or roughly 28 percent of the total discovered across all project categories.
This concentration matters directly to institutional operators: libraries and SDKs form the foundation upon which exchanges, custody providers, and node operators build production systems. A vulnerability in a widely used library can cascade across dozens of downstream applications simultaneously, creating systemic risk that individual project audits may fail to surface.
Among the 4,962 total findings, 720 issues fell into the critical or high-severity categories, meaning roughly one out of every seven reported findings posed material risk. The team identified 85 critical-severity issues specifically, a figure that reflects vulnerabilities requiring immediate remediation to prevent potential loss of user funds, unauthorized access, or network disruption.
Only one reviewed project completed the campaign without any reported findings, underscoring the breadth of the vulnerability landscape across the Bitcoin development ecosystem.
Researchers have already begun notifying affected project maintainers of verified critical findings, including proof-of-concept demonstrations to confirm exploitability. Many maintainers responded quickly to initial reports, though the sheer volume of findings, averaging 166 per hour, presents a significant operational challenge for smaller teams with limited security resources.
The speed at which issues were surfaced now creates a bottleneck at the remediation stage, where maintainers must prioritize, patch, and coordinate disclosure timelines.
Human-Guided AI Uncovered Weaknesses Traditional Audits Typically Miss
The campaign methodology diverged from conventional security audits in a critical way: human researchers actively directed AI tools throughout the testing process rather than running automated scans independently.
Each of the 16 participants employed different prompts, testing strategies, and analytical approaches, a diversity that proved essential to discovering edge cases and context-dependent vulnerabilities.
This collaborative model yielded approximately 2.3 critical or high-severity issues for every person-hour invested, a productivity metric that suggests AI-assisted review can substantially compress the timeline for identifying material defects.
The human-in-the-loop approach mitigates a known limitation of pure automation: AI systems can generate false positives and may miss subtle logical flaws that require domain knowledge to recognize. By having experienced security researchers guide and validate each finding, the campaign created a filter that elevated signal-to-noise ratio while maintaining broad coverage.
The variety in methodology also prevented a single analytical blind spot from systematically missing classes of vulnerabilities, a risk present in any standardized or single-researcher audit.
One contributor submitted findings collected before the live campaign officially commenced, and those results were subsequently incorporated into the final tally. This suggests the 4,962 figure represents work conducted across a slightly extended window, though the core 30-hour window remains the organizing metric for the campaign’s speed advantage.
The inclusion of pre-campaign findings indicates the organizers prioritized comprehensive coverage over strict temporal boundaries, a pragmatic choice that may have increased the total count but also acknowledged that vulnerability discovery is not perfectly synchronous.
Campaign Timing Reflects Rising Institutional Pressure on Bitcoin Infrastructure Security
The security campaign arrived amid heightened ecosystem attention to Bitcoin software vulnerabilities following recent incidents that directly impacted user custody. In late July, attackers exploited defective firmware in Coldcard hardware wallets to compromise seed generation, prompting a wave of wallet sweeps and forcing users to migrate funds.
Bitcoin’s daily active address count surged to 0.98 million on July 31, the highest level since December 2024, as users moved coins in response to the Coldcard vulnerability and broader concern about wallet security practices.
For institutional investors, the timing of this security campaign signals renewed focus on the strength of the software supply chain underlying Bitcoin infrastructure. Custody providers, exchange operators, and node runners depend on the security guarantees embedded in widely used libraries and client implementations.
A critical vulnerability in any of these components can expose institutional positions to theft, operational disruption, or regulatory exposure, making the cost of inadequate security review substantially higher than the cost of the review itself.
The campaign also reflects a shift in how open-source security is being resourced. By coordinating 16 researchers with AI tooling and institutional sponsorship from OpenSats and other entities, the organizers demonstrated that rapid, large-scale vulnerability discovery is feasible without requiring each project to fund its own dedicated audit.
This model may establish a precedent for periodic coordinated reviews of critical Bitcoin infrastructure, reducing reliance on sporadic, project-by-project audits and creating a baseline security standard across the ecosystem.
Remediation Bottleneck and Disclosure Timeline Present Next Operational Challenge
The discovery phase is now complete, but the remediation and disclosure phases, typically longer and more complex, are just beginning. Maintainers across 390 projects must triage, validate, patch, and release updates for thousands of findings while coordinating disclosure timelines to prevent attackers from exploiting publicly known vulnerabilities before fixes are widely deployed.
This coordination problem grows exponentially with the number of affected projects, and no single entity controls the release cycles of independent open-source teams.
The distribution of findings across project categories and severity levels will determine the urgency and complexity of remediation workflows. Critical issues in widely used libraries may trigger immediate patches and coordinated disclosure windows, while lower-severity findings in niche tools may see slower remediation.
Institutional users will need visibility into which findings affect the specific software components and versions they operate, making clear communication from maintainers and coordinating bodies essential to risk management decisions.
The open question now centers on coordination mechanisms for disclosure and patching: whether maintainers will adopt a staggered, coordinated release schedule to minimize the window of public vulnerability, and whether ecosystem participants will maintain a shared registry tracking remediation status across all 390 affected projects. Watch for announcements from OpenSats, OpenCode, and individual maintainers regarding standardized disclosure timelines and for any public guidance from Bitcoin Core developers on prioritization of critical issues affecting node implementations and widely deployed libraries.