By the group's own count the sweep produced 4,962 reports in all, at around $10,000 a day in compute — and it lands while $114 million drains from Coldcard wallets through a flaw that sat unnoticed since 2021.
A team of sixteen unpaid bitcoin developers pointed AI tools at 390 projects tied to bitcoin earlier this month and, on their own count, filed 4,962 vulnerability reports inside 24 hours, 85 of them graded critical and 635 high-severity. Calle, a developer who works under a pseudonym, characterised the situation as extremely bad.
The tally came out of a jointly organised review in which the developers aimed AI models at wallet software, cryptography libraries and infrastructure built for bitcoin. The team reports averaging roughly one critical bug per person per hour, with computing costs running near $10,000 a day.
None of it goes out unchecked, according to Calle: each report is reproduced with a working proof of concept on a local test setup before it reaches a maintainer, and project owners have confirmed the bulk of the critical ones with little delay. The group publishes fast, he says, because maintainers can now verify the results at almost no cost using the same tooling, and because people outside the red team will arrive at the same findings it did.
The ecosystem is already absorbing an episode in which the attackers noticed a weakness first. Sweeps of Coldcard wallets, under way since July 30, have drained as much as $114 million from wallets whose seeds were produced by defective firmware — behind them a flaw dormant since 2021 that, once the range of affected keys was identified, needed no physical access to the device.
The volume of reports is creating trouble of its own. Calle wrote that the ecosystem is in a great deal of chaos at the moment, apologised to maintainers swamped with submissions, and said the group has yet to work out how to filter what he termed the slop.
Rob Hamilton, who is building the automated system the team runs, said the constraint lies not in uncovering bugs but in the coordination it takes to put each one in front of the maintainer who should handle it. The setup is powerful and has surfaced critical issues, he said; he regards it as nothing more than a first version.