Bitcoin’s complexity paradox: How layer-2 scalers became AI's main target Bitcoin infrastructure has suffered a series of major security incidents, including a $114 million drain from Coldcard wallets and a $317 million exploit on Blockstream's Liquid Network, as AI-driven vulnerability scanning uncovers bugs in complex layer-2 code. Bitcoin developer Gregory, CEO of CommerceBlock, said AI is finding bugs that no human can find, and that unused code is no longer safe because AI makes it cheap to analyze. Bitcoin infrastructure has suffered a series of major security incidents in recent months, raising concerns about artificial intelligence making it dramatically cheaper to uncover bugs buried deep inside financial software. Attackers recently drained around $114 million in bitcoin $BTC$77,719.45 from Coldcard wallets, while developers at Core Lightning issued an emergency after AI-generated security reports uncovered genuine vulnerabilities. Most recently, white-hat hackers exploited Blockstream's Liquid Network, withdrawing roughly 4,000 $BTC $317 million before returning 3,400 $BTC after the vulnerability was patched. The vulnerabilities highlight a paradox in Bitcoin’s design. While Bitcoin’s main layer is intentionally simple to minimize risk, the drive to introduce greater utility and speed, through smart contracts and off-chain scaling layers has introduced more complex and potentially more vulnerable codebases. Furthermore, the incidents come as AI is increasingly being used to hunt for vulnerabilities at scale. In August, a group of 16 Bitcoin developers used AI models to sweep 390 Bitcoin projects, producing almost 5,000 findings including 85 initially rated critical. "At some point we have to admit it. AI is finding bugs that no human can find," Gregory said in a Telegram message. Gregory, a bitcoin application developer, previously worked at Merrill Lynch and JPMorgan before co-founding and becoming CEO of CommerceBlock, where he helped develop Bitcoin protocols including MainStay and the statechain implementation behind Mercury Wallet and Mercury Layer. Mercury Layer itself no longer exists, but its open-source code remains on GitHub. Gregory said that AI fundamentally changes what that means for old financial software. "If a model can wake a bug in finance C from 2006, it can probably read a statechain repo that has not moved," he said. Gregory questioned whether overlooked bugs could remain in Mercury's old code, including around key-share deletion, client-side transfer checks, backup transactions and its shrinking locktime mechanism. "That is the new paradigm," Gregory said. "Unused code stopped being unused the moment the cost of reading it dropped to zero."