A large-scale security review of the Bitcoin ecosystem uncovered thousands of potential software vulnerabilities in just 27.5 hours. A volunteer team reported 4,962 findings across 390 Bitcoin projects, including 85 classified as critical.
According to data shared by Calle, the pseudonymous developer behind the Cashu e-cash protocol, 16 Bitcoin developers participated in the review. The team used artificial intelligence models to examine the code of Bitcoin wallets, cryptographic libraries and infrastructure software.
Calle described the situation as “extremely bad.” In addition to the 85 critical vulnerabilities, the findings included 635 issues classified as high severity.
These figures do not mean that thousands of vulnerabilities were found directly in Bitcoin’s core protocol. The review covered open-source wallets, tools and various infrastructure projects connected to Bitcoin.
Critical vulnerabilities reported to project owners
According to Calle, the team is privately disclosing critical findings to the developers responsible for the affected projects instead of releasing them publicly. Project owners quickly verified most of the critical reports.
Before submitting a report, the developers also attempt to reproduce each vulnerability in a local testing environment using a working proof of concept. This process helps filter out inaccurate AI-generated results and provides project teams with findings they can independently verify.
However, the large number of reports generated within such a short period has created another problem. Calle said the ecosystem was experiencing considerable chaos, with project maintainers struggling to process the volume of submissions.
The team does not yet operate a fully automated system. A significant portion of the review still requires human guidance, while developers continue to improve the automated testing infrastructure.
Calle said allowing team members to use their preferred review methods has proved to be the most effective approach so far. The AI models can therefore operate with different testing methods, while developers assess whether the generated reports point to genuine security vulnerabilities.
Rob Hamilton, who is developing the team’s automated review infrastructure, said identifying software vulnerabilities was no longer the main challenge. According to Hamilton, the hardest part is delivering reports to the correct project maintainers and coordinating the remediation process.
The review comes as the Bitcoin ecosystem continues to deal with the consequences of a vulnerability affecting Coldcard hardware wallets. Attacks linked to a software flaw dating back to 2021 have reportedly resulted in the theft of as much as $114 million worth of Bitcoin since July 30.
The attackers involved in the Coldcard incident did not need physical access to the affected devices. A flaw in the firmware made the key space associated with generated seed phrases predictable, allowing the attackers to remotely transfer funds from vulnerable wallets.



