Home
/
Security measures
/
Exchange safety
/

Ai models identify 85 critical bugs post coldcard hack

16 Global Volunteers Uncover 85 Critical Bugs in Bitcoin Projects After Coldcard Hack | Rapid Response Following $100M Loss

By

Maria Gonzalez

Aug 26, 2026, 12:27 PM

Edited By

Jessica Lin

3 minutes reading time

Volunteers using AI to analyze Bitcoin repositories for vulnerabilities after the Coldcard hack

A coalition of 16 volunteers, organized by developers Calle and AnchorWatch CEO Rob Hamilton, rapidly analyzed Bitcoin's open-source codebase using advanced AI models. In just over 27 hours, they identified 4,962 findings across 390 repositories, including 85 critical bugs that some allege attackers exploited prior to full remediation.

Background on Coldcard Hack

The Coldcard incident, resulting in losses surpassing $100 million, prompted a swift response from the Bitcoin community. With funding of approximately $10,000 daily from OpenSats, AI developer Moonshot provided crucial tooling, including the Kimi K3 model.

Key Findings from the Initiative

During a sprint starting on August 4, the volunteers confirmed many critical bug reports and built proof of concept exploits. However, only about 21% of the findings were independently verified within 30 hours. This raises alarms about the ability of project maintainers to address vulnerabilities effectively, with fewer than 5% of projects receiving formal disclosures.

Exploitation of Vulnerabilities

Interestingly, during this time, a critical vulnerability in the BTCPay Server was exploited, draining Lightning nodes linked to it by stealing macaroon credential files. One notable case involved Foundation, a hardware wallet company, suffering an attack on its BTCPay Lightning node overnight.

"This specific vulnerability had already been reported to BTCPay by Red Team members," noted an expert.

Despite the proactive measures taken by the Red Team, the discoverability of critical bugs does not match up with the speed of remediation.

Community Reactions

Several participants expressed concern about the ongoing risks associated with self-hosted services:

  • Some believe the responsibility for applying repairs lies heavily on individual operators.

  • Others raised alarms about the staggering number of unverified findings (around 4,000), which can create a chaotic environment for maintainers.

Selected Quotes

  • "It's wild that weโ€™re at the point where the bottleneck is just humans not being able to keep up with the machines."

  • "Reporting a bug in software people run themselves starts a clock the person who fixed it doesnโ€™t control."

Key Takeaways:

  • ๐Ÿ” Volunteers identified 4,962 findings in Bitcoin projects within 27 hours.

  • โš ๏ธ 85 critical vulnerabilities confirmed by project owners, yet fewer than 5% received formal disclosure.

  • โšก Attackers exploited BTCPay Server vulnerabilities despite prior reporting by the Red Team.

  • ๐Ÿšง Only 21% of findings were verified independently by the 30-hour mark.

As AI tools improve detection capabilities, the pressing question remains: How can the community ensure swift action on identified vulnerabilities? The ongoing situation represents not only a challenge but also an opportunity for the Bitcoin ecosystem to strengthen its security measures.

Predictions on the Horizon

Thereโ€™s a strong chance that the Bitcoin development community will ramp up its efforts to address the identified vulnerabilities. As more people become aware of the ongoing risks, experts estimate around 30-40% of projects may implement urgent updates within the next few months. Increased collaboration among developers and possibly the formation of formal task forces to tackle these vulnerabilities could emerge, enhancing the pace of remediation. This combined response may also lead to a shift in community dynamics, prompting a reevaluation of accountability for self-hosting services. If these changes take hold, we could see more robust frameworks and standards for addressing security flaws.

A Unique Lens on Past Challenges

Reflecting on past events, the current situation bears a resemblance to the rapid response seen in the aftermath of the Y2K scare. In that case, stakeholders pooled resources and mobilized quickly to address looming threats in software systems globally. Just as organizations then adjusted coding practices and built more structured protocols to prevent issues, the Bitcoin community may find itself on the brink of adopting new security measures. This history suggests that while the challenges are daunting, collaborative responses can lead to solid improvements in overall system resilience, setting a foundation for a more secure future.