Particle.news
Download on the App Store

Volunteer AI Audit Flags Nearly 5,000 Bitcoin Flaws as OpenAI Access Is Restricted

The rapid scan exposed hundreds of high‑severity bugs and revealed that platform rules can block defenders from using U.S. AI tools.

Overview

  • A volunteer Bitcoin Red Team using AI tools reported 4,962 security findings across about 390 open‑source Bitcoin projects after roughly 30 hours of scanning.
  • Of those findings, about 720 were rated high or critical in severity and only 147 of those serious reports have been communicated to the projects that must fix them.
  • The audit was launched after a late‑July Coldcard hardware‑wallet flaw caused predictable seed generation and confirmed thefts measured in the low thousands of BTC, prompting urgent ecosystem review.
  • Lead researcher Rob Hamilton said OpenAI limited his access to Trust and Cyber tools during the work, which forced the team to pivot to Chinese open‑source models such as Kimi K3 and later regain some access.
  • The project relied heavily on automated scanning—around 91% of findings—with about 21% including working proof‑of‑concept code, creating a disclosure and remediation bottleneck that has prompted OpenSats to fund researchers through a Code RED grant track.