A volunteer security initiative is using frontier AI models to stress-test Bitcoin's software stack, and the early results suggest the ecosystem has more exposed surface area than developers assumed. The group, known as Bitcoin Red Team and organized by AnchorWatch CEO Rob Hamilton alongside pseudonymous developer Calle, says it has scanned 150 Bitcoin repositories, disclosed more than a dozen vulnerabilities, and is building an open-source AI platform to automate future security reviews.

Hamilton said the effort has burned through roughly $20,000 in AI compute spend so far, at a pace of about $10,000 a day, running reviews through a stack of frontier models that includes Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable and Opus, and Z.ai's GLM 5.2. Calle described the discovery rate in blunt terms: “we're averaging on the order of one critical exploit per hour per person.”

gold and silver round coin
Photo by Kanchanara on Unsplash

The Tally Has Grown Fast

The scale of the campaign expanded quickly after the initial disclosures. Later reporting put the campaign's footprint at 390 repositories reviewed and 4,962 potential issues logged, of which 720 were classified as high- or critical-severity, with more than 4,900 of those findings filed inside a single 27.5-hour stretch. The effort was reportedly triggered in part by a recent Coldcard hardware wallet exploit that renewed concerns about AI-assisted attackers probing Bitcoin infrastructure ahead of defenders.

Why the Numbers Are So High

Red Team's targets span wallets, cryptographic libraries and core infrastructure rather than a single project, which helps explain the scale of the count — a high volume of AI-generated findings still requires manual triage, and not every flagged issue rises to a genuine, exploitable bug. Hamilton's team has been reaching out directly to maintainers of affected open-source projects, a process the reporting describes as unsettling for engineers on the receiving end of an unsolicited message flagging a critical flaw in their code.

Related: Saylor Says AI-Designed Instruments Helped Strategy Raise $15B

Part of a Broader Pattern

The initiative fits into a wider trend of AI-driven security auditing spreading across crypto, following earlier high-profile discoveries such as the 2020 Zcash cryptographic flaw. Whether Bitcoin Red Team's platform becomes a standing part of how core Bitcoin software gets reviewed will likely depend on how many of its thousands of flagged issues hold up as genuine, previously unknown vulnerabilities once maintainers finish triaging them.