Approximately one in seven reported findings was categorised as having high or critical severity. A coordinated Bitcoin security campaign identified nearly 5,000 software issues across hundreds of open-source projects in approximately 30 hours. The initiative integrated human expertise with artificial intelligence tools to pinpoint software vulnerabilities. The initiative convened 16 security researchers under the leadership of developer Calle, with backing from OpenSats, OpenCode, and sponsors of AI inference. The group collaborated on a comprehensive review encompassing numerous Bitcoin-related projects. According to figures released by the team, researchers reported 4,962 findings across 390 Bitcoin-related projects during the campaign.
The total encompassed 85 critical issues and 635 high-severity findings, resulting in a cumulative count of 720 of the most serious reports. The campaign sustained a brisk tempo, with an average of approximately 166 reported findings per hour during the review process. According to the published figures, the team determined approximately 2.3 critical or high-severity issues for each person-hour dedicated to software examination. Researchers indicated that the campaign diverged from a conventional security audit due to the involvement of human reviewers who actively directed AI systems throughout the testing process. Each participant employed distinct prompts and methodologies, facilitating the identification of vulnerabilities that a singular approach may have overlooked.
The final tally also encompassed findings gathered by one contributor prior to the official commencement of the live campaign. Following the inclusion of those results, crypto libraries and software development kits accounted for the most significant portion of findings, with 1,385 reported issues. The team indicated that approximately one in every seven reported findings was classified within the high or critical severity categories. Only one reviewed project reportedly completed the campaign without any reported issues, prompting a light-hearted remark from Bitcoin Core developer Matt Corallo. Researchers have commenced the process of delivering verified critical findings to the relevant project maintainers, accompanied by supporting proof-of-concept retest demonstrations.
Numerous maintainers have reportedly validated the reports swiftly, yet managing such a substantial volume continues to pose a considerable challenge. The campaign emerges in response to the heightened focus on Bitcoin software security throughout the ecosystem, following a series of recent security incidents. On July 31, Bitcoin registered approximately 0.98 million daily active addresses, marking the highest figure since December 2024. The surge occurred following the actions of attackers who targeted wallets with seeds created thru flawed Coldcard firmware.