|

Bitcoin’s AI security sprint found 6,700 issues in 55 hours, but no one knows how many are real

Infographic showing Bitcoin Red Team

AI-assisted security marketing campaign targeted on the Bitcoin ecosystem, Bitcoin Red Team, stated it generated 6,700 findings throughout 425 initiatives in its first 55 hours. The marketing campaign labeled 1,029 of them high or essential.

The Aug. 6 replace measures how a lot materials entered a security triage pipeline, and its impact on software program security stays unreported.

The retrieved thread omitted audit-ready definitions and denominators for the severity counts, in addition to case-level outcomes, an mixture false-positive charge, and a repair charge.

Those lacking fields forestall a calculation of how many alerts grew to become confirmed vulnerabilities, how many maintainers rejected or downgraded, and how many led to patches.

The first 55 hours nonetheless reveal a consequential functionality, noting how AI programs can fill an ecosystem-scale evaluate pipeline shortly. Expert prompting, replica, disclosure, and maintainer response remained vital at each later stage.

What the marketing campaign numbers measure

The marketing campaign revealed two snapshots as its roster and workload expanded:

(*55*)

Elapsed time Projects Total findings Reported severity Participants
27.5 hours 390 4,962 85 essential; 635 high 16
55 hours 425 6,700 1,029 high or essential 24 reported, together with three bots

The 27.5-hour update coated 390 initiatives and 4,962 findings. By the 55-hour mark, the mission depend had risen by 35 and the discovering depend by 1,738. The later thread put high-or-critical findings at 15.4% of the whole and clarified that three of the 24 reported individuals have been bots.

The earlier put up separated essential and high findings, whereas the later one mixed them, with each units of figures reflecting marketing campaign assessments. Maintainer-confirmed exploitability and remediation outcomes require separate proof.

Infographic showing Bitcoin Red Team's campaign-reported 55-hour totals, human review workflow, disclosure contact gaps, and unpublished false-positive and fix rates.
Bitcoin Red Team scanned 425 initiatives and reported 6,700 findings, together with 1,029 high or essential issues, whereas public validation charges stay unpublished.

Rob Hamilton described Kimi K3 as dealing with the heavy evaluation, with GPT Sol, Fable/Opus, and GLM 5.2 supporting the documentation. He stated OpenAI’s Cyber Harness coated chosen elements he thought of load-bearing.

A day later, Hamilton wrote that subject-matter specialists could change an assessment with one or two sentences of context or a small block of code. In examples he described, that enter pushed middling issues into high or essential territory. He additionally recognized operations, disclosure handoff, and triage as bottlenecks.

In Hamilton’s account, fashions searched broadly whereas specialists formed prompts, interpreted output, tried replica, and determined which reviews have been prepared for disclosure. That division of labor makes the marketing campaign a human-AI evaluate system.

OpenAI’s new cybersecurity push has a lesson for crypto: stop waiting for the hack
Related Reading

OpenAI’s new cybersecurity push has a lesson for crypto: stop waiting for the hack

OpenAI’s Daybreak may point to the crypto industry’s next security standard of becoming resilient before vulnerabilities are exploited.
May 12, 2026
·
Gino Matos

The developer generally known as Calle stated most important reviews have been quickly verified by project owners. The put up equipped no denominator, verified-report depend, rejection depend, or patch standing, leaving the breadth and final result of that verification unresolved.

Firefox finds 20 year old bug and patches 14 months of fixes in 30 days using Anthropic’s Mythos AI
Related Reading

Firefox finds 20 year old bug and patches 14 months of fixes in 30 days using Anthropic’s Mythos AI

Mozilla’s 20-year Firefox bug shows the risk of AI-accelerated zero-day discovery
May 10, 2026
·
Liam ‘Akiba’ Wright

Outreach and outcomes outline the security worth

In the 55-hour replace, Bitcoin Red Team reported that 19.5% of scanned initiatives had a SECURITY.md file and 13.1% had an electronic mail there. The retrieved thread omitted the mission corpus, denominator interpretation, and measurement methodology, so the chances solely describe the marketing campaign’s scan.

On Aug. 3, Hamilton stated the hassle had spent over $10,000 scanning over 100 repositories and had instantly disclosed essential findings when a proof of idea demonstrated exploitability. On Aug. 4, he reported about $20,000 in spending, greater than a dozen disclosures and 150 repositories scanned.

Scanning continued to broaden, whereas the marketing campaign described outreach, handoff and triage as lively operational constraints. The revealed snapshots provide no comparable disclosure denominator at 55 hours, so they can’t set up the relative velocity of scanning and backbone.

Hamilton later recognized the separate Coldcard incident as a catalyst for the wider campaign. The marketing campaign report attributes no discovery of the Coldcard flaw to this sprint.

Coldcard’s $89M wallet bug triggers the biggest Bitcoin movement since FTX and completely distorts market signals
Related Reading

Coldcard’s $89M wallet bug triggers the biggest Bitcoin movement since FTX and completely distorts market signals

More than 77,000 BTC moved from older wallets as users raced to secure funds, complicating bearish readings across key on-chain indicators.
Aug 2, 2026
·
Oluwapelumi Adejumo

A helpful public accounting would separate findings that have been reproduced, acknowledged, downgraded, rejected, and glued, with definitions and denominators for every charge. That breakdown would present how a lot of the marketing campaign’s quantity grew to become actionable security work.

A public critic, JW Weatherman, argued that the marketing campaign could not triage its output. His put up recognized no campaign-linked situation, patch, or advisory, so it provides criticism and not using a measurable failure charge. The marketing campaign’s lacking disposition information leaves the underlying query open.

For now, 6,700 represents campaign-labeled findings and triage candidates. The sprint demonstrated the velocity of machine-assisted evaluate. Its lasting security worth depends upon the share that specialists can validate, disclose, and convert into fixes.

The put up Bitcoin’s AI security sprint found 6,700 issues in 55 hours, but no one knows how many are real appeared first on CryptoSlate.

Similar Posts