Core Summary
A volunteer security research team has discovered 85 critical-level vulnerabilities in Bitcoin’s core codebase using AI models for systematic code scanning. The team described the situation as “extremely bad,” revealing that they are averaging roughly one critical bug per hour per person, with daily compute costs of approximately $10,000. The discovery has prompted urgent security patch efforts from the Bitcoin Core development team.
Event Details
According to CoinDesk, the independent team of security researchers launched a large-scale AI-assisted audit of Bitcoin Core’s C++ codebase. Using advanced AI models, they conducted line-by-line scanning to identify potential security vulnerabilities and logic defects.
The team leader described the results as shocking. “We’re averaging one critical bug per person per hour, which is far beyond expectations,” he said. “This is an extremely bad situation.” The 85 confirmed critical vulnerabilities could potentially lead to node crashes, fund losses, or network forks.
The project’s operating costs are substantial. The leader revealed daily compute costs of approximately $10,000, primarily for running AI models and processing massive code data. Despite the high cost, this investment is considered necessary given Bitcoin’s market capitalization of hundreds of billions of dollars.
The Bitcoin Core development team has responded quickly, beginning to prioritize and patch these vulnerabilities. Some may have been indirectly fixed through previous updates, but many require dedicated security patches. The community expects a series of emergency security updates in the coming weeks.
Panoramic Analysis
This event has profound implications for Bitcoin and the broader blockchain industry. First, it reveals the security auditing challenges facing large open-source projects. Bitcoin Core’s codebase has grown over more than a decade of development, becoming vast and complex. Traditional manual auditing struggles to cover all potential risks. AI-assisted auditing offers a new security assurance approach for open-source projects.
Second, this event highlights AI’s enormous potential in code security. AI models can rapidly identify pattern anomalies, logic vulnerabilities, and potential attack vectors far more efficiently than manual auditing. In the future, AI-assisted security auditing may become standard practice for blockchain projects, potentially spawning a dedicated AI security audit services market.
However, this event also raises questions about the limitations of AI security auditing. AI models themselves may produce false positives or miss vulnerabilities, and the quality of their findings depends on training data and algorithm design. Additionally, efficiently patching and deploying fixes after AI discovers vulnerabilities remains challenging. Bitcoin’s decentralized nature means node upgrades require network-wide consensus, potentially limiting patch deployment speed.
From a broader perspective, this event reflects the blockchain industry’s growing maturity. Early blockchain projects focused more on functional innovation than security auditing. As the industry scales and regulation tightens, security has become a core survival factor. The Bitcoin community’s proactive disclosure and repair efforts demonstrate their commitment to network security and help build public trust.
Multiple Perspectives
Security Researchers: Multiple independent security researchers expressed concern. “85 critical bugs is a staggering number,” one blockchain security expert said. “It shows that even code audited for over a decade may still contain unknown risks. AI-assisted auditing is changing the game.”
Bitcoin Core Developers: The core team emphasized that vulnerability discovery reflects the security process working as intended. “Open-source projects benefit from transparency and community collaboration,” one core developer said. “We appreciate the volunteers’ contributions and will prioritize fixing these vulnerabilities.”
Industry Response: Some blockchain companies expressed interest in AI-assisted auditing. “This could become the standard approach for future security audits,” one smart contract audit firm representative said. “We’re evaluating how to integrate AI into our audit processes.”
Skeptical Voices: Some experts remain cautious about AI auditing reliability. “AI models may produce false positives,” one cryptography expert noted. “We need independent verification of these vulnerabilities’ authenticity and severity to avoid unnecessary panic.”
Editor: GoodInfo Global News Team