Original Author: Forbes
Original Compilation: AididiaoJP, Foresight News
Bitcoin and cryptocurrency traders have yet to recover from a large-scale attack worth approximately $100 million, which once sparked fears of a new round of price crashes.
Since news of the attack on the hardware wallet Coldcard first emerged, Bitcoin's price has rebounded but remains hovering near recent lows. Traders are generally on edge, fearing another severe shock.
Against this backdrop, Bitcoin developers have used an AI tool to uncover nearly 5,000 security vulnerabilities across nearly 400 projects in just 24 hours. The situation was directly described as "extremely bad."
A team of volunteer Bitcoin developers is conducting a large-scale, coordinated security audit. They have confirmed that the overall security state of the ecosystem is "extremely bad."
Within 24 hours, they scanned about 390 Bitcoin-related projects, discovering a cumulative 4,962 security vulnerabilities, including 85 critical and 635 high-severity ones. The vast majority of the vulnerabilities have been validated by the respective project teams.
"We have grown to 16 people, globally distributed, working in shifts around the clock," Calle, an anonymous developer of the Cashu ecash protocol, wrote on X. "We are conducting a large-scale ecosystem security audit of the Bitcoin codebase."
The audit team is using Moonshot's Kimi K3 model—an open-weight AI tool from China. Calle revealed that the team spends about $10,000 daily on computing power, a cost covered by OpenSats.
"We have been working day and night," Rob Hamilton, CEO of Bitcoin insurance company AnchorWatch and an audit team member, also stated on X, noting that the team has already found some "critical issues."
The efficiency of this audit is astonishing. One developer noted that, on average, they are uncovering roughly one critical vulnerability per hour. AI is becoming an accelerator for both defenders and attackers—a trend that began to surface in the recent Coldcard incident.
Over the past year, Bitcoin's price has already declined significantly, making the market highly sensitive to further drops. The sudden outbreak of the hardware wallet security incident has pushed the question "Is self-custody really safe?" back to the forefront.
Last week, the Coldcard Bitcoin hardware wallet was exploited, with nearly 2,000 Bitcoins (valued just over $100 million) drained from more than 5,200 addresses in just a few days. The attacker exploited a five-year-old key generation flaw.
The Coldcard team has urgently called on users to move their funds and repeatedly pleaded on social media for everyone to "help spread the word."
"Please treat this as an emergency," the official Coldcard account wrote. "Move your funds immediately. Follow the recommended steps for your device model, update the device, generate a new seed, and carefully transfer funds... The threat is ongoing."
A wallet address associated with the hacker still holds approximately $36 million worth of Bitcoin, most of which is believed to be stolen. Since the incident came to light, this address has continued to receive multiple deposits, some with messages attached via Bitcoin's OP_RETURN function.
One message read: "I launder BTC, do KYC, and cash out. I charge 10%." This is interpreted as a solicitation for money laundering, attempting to turn the hacker into a client. Other messages were direct pleas for the return of the stolen Bitcoin.
Some on-chain analysts point out that the vulnerability is now public, with extremely high visibility, and cutting-edge large models are almost universally accessible. This means multiple hacking groups may be simultaneously researching how to expand their gains. "You're racing against time."
Cobra, an anonymous co-owner of Bitcoin.org, stated bluntly that he has a "very bad feeling"—AI likely played a role in the Coldcard fund drainage event.
This AI-driven vulnerability scanning, coupled with the previous large-scale theft from Coldcard, is pushing Bitcoin ecosystem security issues to a new critical point. While developers use AI to accelerate vulnerability discovery, attackers may use the same tools to accelerate exploitation. The window for patching and migration in between is being compressed.
Currently, Bitcoin's price continues to fluctuate at low levels, with traders awaiting the next potential shock. And this audit, burning through $10,000 in computing power daily, may only be the beginning of a broader security sweep.








