Bitcoin developers flag 85 critical bugs in an “extremely bad” situation
A volunteer group running AI models against bitcoin codebases says it is averaging roughly one critical bug per hour per person, at about $10,000 a day in compute.
- Sixteen Bitcoin developers used AI tools to find 4,962 security vulnerabilities across 390 projects in 24 hours.
- The findings include 85 critical and 635 high-severity bugs, which are currently overwhelming project maintainers.
- This audit highlights how AI is rapidly transforming security research for both defenders and attackers.
Most of the critical reports have been quickly verified by project owners, Calle said, and are being reproduced using a working proof of concept in a local test environment before being sent.
But he acknowledged the volume is creating problems of its own.
“There’s a lot of chaos right now in the ecosystem,” he wrote, apologizing to maintainers buried in reports and saying the group is still learning to sort out “the slop.”
The group publishes fast because maintainers can now verify findings almost for free using the same tools, Calle said, and because “others who aren’t on the red team will arrive at the same findings as we did.”

