A 30-hour initiative led by developer Calle and supported by OpenSats and OpenCode has identified nearly 5,000 software vulnerabilities across 390 Bitcoin-related projects, highlighting systemic risks in the ecosystem. The effort, which leveraged AI tools reviewed by human analysts, revealed 85 critical and 635 high-severity issues, with findings concentrated in cryptographic libraries and software development kits.
The campaign, involving 16 security researchers, achieved an average of 2.3 critical or high-severity issues per person-hour, underscoring the scale of challenges in maintaining secure code across the Bitcoin infrastructure. Over 1,385 vulnerabilities were flagged in libraries and SDKs, which are foundational to many applications in the space.
One project reportedly emerged without any reported issues, prompting a lighthearted comment from Bitcoin Core developer Matt Corallo, though the exact nature of his remark remains unspecified. The findings have not yet been fully processed, with the extent of remediation efforts unclear.
The use of AI inference tools, though not disclosed by their sponsors, appears to have accelerated the detection process. However, the campaign’s organisers have not yet provided details on how the identified issues will be prioritised or addressed by the affected projects.
Written by James Tobias
Bitcoin Desk