AI-Powered 'Bitcoin Red Team' Uncovers Thousands of Potential Code Flaws, But Fixes Lag Behind
Rob Hamilton, CEO of AnchorWatch and a Bitcoin contributor, recently had his first code fix accepted into Bitcoin Core, a patch for a wallet-related bug discovered by pointing AI models at the project's codebase. The fix is part of a larger volunteer effort called the Bitcoin Red Team, which uses AI tools to audit Bitcoin-related open-source software for security flaws.
In a 30-hour push involving 17 volunteers, the team logged 4,962 findings across more than 390 repositories, including 85 rated critical and 635 rated high severity. The project grew out of Hamilton's earlier experiments and was accelerated after a Coldcard hardware wallet vulnerability led to the theft of more than 1,000 BTC in July. Midway through the effort, OpenAI cut off Hamilton's access to its tools for this work, forcing the team to switch to alternative AI systems to keep scanning.
Hamilton himself flagged the project's biggest weakness: AI can find issues far faster than humans can fix them. Thousands of findings emerged in just 30 hours, but getting maintainers across hundreds of repositories to review, verify and patch them is a slow, manual process, illustrated by the fact that only one commit has been merged so far.
Key Takeaway: AI tools can rapidly surface security issues in code, but businesses should remember that detection is only useful if paired with a realistic process for triaging and fixing what's found.