Bitcoin developers flag 85 critical bugs in an “extremely bad” situation

BTC news: Some Bitcoin developers say they’re finding a critical bug every hour

Tech

A volunteer group running AI models against bitcoin codebases says it is averaging roughly one critical bug per hour per person, at about $10,000 a day in compute.

By Shaurya Malwa|Edited by Omkar Godbole

Updated Aug 6, 2026, 7:53 a.m. Published Aug 6, 2026, 7:14 a.m.

2min read

Share this article

A bug walking across a keyboard. Developers are increasingly discovering software bugs using AI. (Unsplash)

Summary

A volunteer team has flagged 85 critical bugs across 390 bitcoin BTC$64,785.85 projects in a little over a day.

Sixteen Bitcoin developers have filed 4,962 findings in a coordinated security audit, including 85 critical and 635 high-severity issues, according to Calle, the pseudonymous developer behind the Cashu ecash protocol.

The findings come from a coordinated audit run by developers pointing AI models at bitcoin wallets, cryptographic libraries and infrastructure.

“Situation is extremely bad,” Calle noted.

Most of the critical reports have been quickly verified by project owners, Calle said, and are being reproduced using a working proof of concept in a local test environment before being sent.

But he acknowledged the volume is creating problems of its own.

“There’s a lot of chaos right now in the ecosystem,” he wrote, apologizing to maintainers buried in reports and saying the group is still learning to sort out “the slop.”

The group publishes fast because maintainers can now verify findings almost for free using the same tools, Calle said, and because “others who aren’t on the red team will arrive at the same findings as we did.”

Rob Hamilton, who is building the automated setup the group runs, said in an X post the bottleneck is not finding bugs but routing them to the right maintainers.

“The hardest part is coordinating to get things to the right people,” Hamilton wrote. “While it is powerful, having found critical issues, I would view this as only version one.”

The audit lands in an ecosystem already absorbing the fallout when the other side finds a flaw first.

The Coldcard sweeps, which began July 30 and have taken as much as $114 million from wallets whose seeds were generated by faulty firmware, stemmed from a bug that had been dormant since 2021 and required no access to the physical device once the affected key space was known.

Attackers already have the same tools, however.

Anthropic said in April that one of its models, held back from public release and given only to vetted users, found a bug that had sat undiscovered in widely used software for 27 years, at a cost of less than $50. It found flaws in the encryption software that secures banking connections, exchange logins and the servers running most of the internet.

Separately, Google’s threat intelligence team said in May it had caught a criminal group preparing an attack built on a flaw a model had found for them.

Related Assets

By CoinDesk Research

Jun 29, 2026

Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.

Why it matters:

Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.


 

Leave a Reply

Your email address will not be published. Required fields are marked *