# Bitcoin Red Team Says AI Is Finding Critical Exploits Across Core Projects

> Source: <https://decrypt.co/375169/bitcoin-red-team-ai-finding-critical-vulnerabilities>
> Published: 2026-08-08 17:31:03+00:00

#### In brief

- The initiative says it has scanned about 150 Bitcoin repositories and made more than a dozen vulnerability disclosures.
- The team is developing an open-source AI platform for auditing Bitcoin software.
- Developers say the effort is uncovering critical vulnerabilities across wallets, cryptographic libraries, and infrastructure.

A volunteer security initiative says it used frontier AI models to scan 150 Bitcoin repositories and found more than a dozen vulnerabilities as developers increasingly use artificial intelligence to audit blockchains.

In a [post](https://x.com/Rob1Ham/status/2084523368783438198?s=20) on X earlier this week, AnchorWatch CEO Rob Hamilton said the group has spent about $20,000 on AI services while building a "Bitcoin red team" platform.

“We have been working around the clock, with ~$20,000 of spend up to this point across different services,” he wrote. “Funding is secured, I appreciate all the gestures for donations but it is not necessary. The bill is taken care of.”

A [red team](https://decrypt.co/373613) refers to cybersecurity professionals who test software from an attacker's perspective, probing for vulnerabilities before they can be exploited.

According to Hamilton, the Bitcoin red team uses [Kimi K3](https://decrypt.co/373716/china-kimi-k3-largest-open-source-ai-model-ever-beats-claude-fable-gpt-5-6-sol) alongside [OpenAI’s GPT Sol](https://decrypt.co/373151/openai-gpt-5-6-sol-how-compares-ai-models), Anthropic’s [Claude Fable and Opus models](https://decrypt.co/374305/claude-opus-5-outscores-fable-5-most-benchmarks-half-price), and [Z.ai’s GLM 5.2](https://decrypt.co/371613/china-z-ai-glm-5-2-model-rivals-claude-opus) to identify vulnerabilities and generate supporting documentation.

“We also have been connected with OpenAI for some help so I could manage getting the Cyber Harness running as well,” he wrote. “It's a much more expensive scan, but well worth it for load-bearing portions of the Bitcoin ecosystem and has already yielded good results.”

Pseudonymous Bitcoin developer Calle said the initiative has built multiple AI-powered review systems targeting wallets, cryptographic libraries, infrastructure, and other Bitcoin projects.

"We're averaging on the order of one critical exploit per hour per person,” Calle [wrote](https://x.com/callebtc/status/2084561246305542617?s=20) on X. “We've reported critical vulnerabilities to several projects in the last 12 hours. Thankfully, this is a very expensive exercise. We're burning through $10,000 per day."

The team did not disclose which projects were affected or provide details of the vulnerabilities.

The announcement comes as AI is playing a growing role in finding security flaws across the crypto industry. Earlier this year, researchers using Anthropic's [Claude Opus 4.8](https://decrypt.co/369384/anthropic-claude-opus-4-8-better-ai-coding-smarter-safety-huge-price) uncovered a four-year-old [flaw](https://decrypt.co/370184/zcash-crash-wiped-billions-market-cap-can-zec-recover) in Zcash that could have allowed attackers to create unlimited counterfeit ZEC. In August, Coinkite said it believes attackers used AI to identify the [Coldcard](https://decrypt.co/374914/ledger-coldcard-exploit-bitcoin-wallet-security-ai) wallet vulnerability, while Bitcoin bridge Boltz [suspended](https://decrypt.co/374933/bitcoin-bridge-shuts-down-ai-finding-bugs-too-fast) its swap service after saying attackers were using AI to identify vulnerabilities faster than its team could patch them.
