Bitcoin developers flag 85 critical bugs in an “extremely bad” situation

A volunteer team has flagged 85 critical bugs across 390 bitcoin BTC$64,785.85 projects in a little over a day.

Sixteen Bitcoin developers have filed 4,962 findings in a coordinated security audit, including 85 critical and 635 high-severity issues, according to Calle, the pseudonymous developer behind the Cashu ecash protocol.

The findings come from a coordinated audit run by developers pointing AI models at bitcoin wallets, cryptographic libraries and infrastructure.

"Situation is extremely bad," Calle noted.

We're ramping up.
Much of our work is still manual (hand holding the AI) but our automated harnesses are getting better at the same time.
So far, letting everyone use their own favorite review method has proven to be the most effective strategy.
We're getting a lot of… pic.twitter.com/EoS6Z9ubpr

— calle (@callebtc) August 5, 2026

Most of the critical reports have been quickly verified by project owners, Calle said, and are being reproduced using a working proof of concept in a local test environment before being sent.

But he acknowledged the volume is creating problems of its own.

"There's a lot of chaos right now in the ecosystem," he wrote, apologizing to maintainers buried in reports and saying the group is still learning to sort out “the slop.”

The group publishes fast because maintainers can now verify findings almost for free using the same tools, Calle said, and because "others who aren't on the red team will arrive at the same findings as we did."

Rob Hamilton, who is building the automated setup the group runs, said in an X post the bottleneck is not finding bugs but routing them to the right maintainers.

"The hardest part is coordinating to get things to the right people," Hamilton wrote. "While it is powerful, having found critical issues, I would view this as only version one."

The audit lands in an ecosystem already absorbing the fallout when the other side finds a flaw first.

The Coldcard sweeps, which began July 30 and have taken as much as $114 million from wallets whose seeds were generated by faulty firmware, stemmed from a bug that had been dormant since 2021 and required no access to the physical device once the affected key space was known.

Attackers already have the same tools, however.

Anthropic said in April that one of its models, held back from public release and given only to vetted users, found a bug that had sat undiscovered in widely used software for 27 years, at a cost of less than $50. It found flaws in the encryption software that secures banking connections, exchange logins and the servers running most of the internet.

Separately, Google's threat intelligence team said in May it had caught a criminal group preparing an attack built on a flaw a model had found for them.