The Bitcoin AI security audit reported 4,962 findings across 390 projects, including 85 critical findings and 635 high-severity findings. This introduction states the main headline fact and key numbers for immediate reference and omits detailed explanations or quoted material, and does not provide incident timelines, technical reproduction details, or remediation steps. It lists only the aggregate totals and the severity breakdown to present a precise numeric snapshot of the audit that stakeholders and maintainers can consult quickly without additional context or procedural information or analysis readily in this section now.
The audit ran for roughly 30 hours and involved 16 people working around the clock across multiple locations. The contributor tally included 17 contributors in total, of which 14 were human and 3 were automated. The team was supported by AI-assisted scanning alongside human operators to maintain continuous coverage during the campaign.
The methodology used an AI-driven audit process with an automated scan intake that accounted for 91% of all findings. Automated tooling triaged, flagged, and funneled results into the intake pipeline for further handling by contributors. Human reviewers and automated contributors both participated in processing the intake.
The audit produced an average of 1.85 serious issues per project and operated at an observed rate of approximately 166 findings per hour. These throughput and per-project metrics were calculated from the audit’s runtime and contributor activity. The methodology combined high-frequency automated detection with human validation steps to manage the volume.
During the Bitcoin AI security audit campaign, significant issues were discovered related to Coinkite’s Coldcard wallet. These findings highlighted vulnerabilities in the firmware that were linked to substantial financial losses. Specifically, a firmware issue in 2021 was associated with a $130 million loss, where up to $114 million in losses were attributed to Coldcard seeds being generated by faulty firmware.
These findings were part of a comprehensive audit that spanned 390 Bitcoin projects, aiming to uncover and address potential security threats in various aspects of the Bitcoin ecosystem. This particular case stands out due to the high financial impact and underscores the importance of robust security practices in cryptocurrency technologies.
Audit outcomes included that 21% of findings were dynamically reproduced with proof of concept (PoC). Nineteen projects, representing under 5% of those reviewed, had findings disclosed upstream. Eight findings were retired as false positives during the campaign. These outcome metrics were reported alongside other operational statistics without restating aggregate totals in this section.
Calle said, “There’s a lot of chaos right now in the ecosystem.” Calle also said, “The hardest part is coordinating to get things to the right people.” Calle added that “validation is now nearly free with AI.”
Those remarks appeared in the campaign’s situation report and were recorded as part of the audit’s public reporting on operational and validation challenges.
The Bitcoin AI security audit identified security issues across a broad set of projects and underscored the scale of vulnerabilities detected during the campaign. The audit demonstrated the operational value of an AI-driven approach in scaling detection, intake processing, and validation to handle high volumes of findings within a condensed timeframe.


