BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Kimi K3 Uncovers 5,000 Security Vulnerabilities in a Day: Is the Bitcoin Ecosystem's Security at Risk?

Foresight News
特邀专栏作者
2026-08-07 12:00
This article is about 1559 words, reading the full article takes about 3 minutes
AI Audits Sound the Alarm on Bitcoin Security.
AI Summary
Expand
  • Core Takeaway: A team of Bitcoin developers used AI tools to audit nearly 400 projects within 24 hours, uncovering nearly 5,000 security vulnerabilities and highlighting an "extremely poor" state of industry security. Meanwhile, the Coldcard hardware wallet was attacked and saw $100 million stolen, revealing that AI is simultaneously accelerating both attackers' exploit capabilities and defenders' remediation efforts.
  • Key Elements:
    1. A team of 16 global volunteers used Moonshot's Kimi K3 model to scan approximately 390 Bitcoin projects, discovering 4,962 vulnerabilities, including 85 critical-level and 635 high-level flaws. The daily computing cost of approximately $10,000 was funded by OpenSats.
    2. The Coldcard hardware wallet was exploited due to a key-generation flaw that had existed for five years, resulting in approximately 2,000 bitcoins (worth over $100 million) being stolen from more than 5,200 addresses. The team urgently called on users to migrate their funds.
    3. An address linked to the hacker still holds approximately $36 million in bitcoin, most of which was stolen, and has received money-laundering solicitations and return requests via the OP_RETURN function.
    4. Cobra, the anonymous co-owner of Bitcoin.org, expressed concern that AI may have already been involved in the Coldcard theft, suggesting attackers may have leveraged cutting-edge large language models to simultaneously expand their gains.
    5. Over the past year, Bitcoin's price has fallen significantly, making the market highly sensitive to further declines. The hardware wallet security incident has reignited questions about the safety of "self-custody."

Original author: Forbes

Original translation: AididiaoJP, Foresight News

Bitcoin and crypto traders are still reeling from a massive attack worth approximately $100 million, which briefly ignited fears of another round of price crashes.

Since news of the hardware wallet Coldcard breach first broke, Bitcoin's price has bounced back somewhat but remains near recent lows. Traders are generally on edge, bracing for another sharp shock.

Against this backdrop, Bitcoin developers using AI tools have uncovered nearly 5,000 security vulnerabilities across close to 400 projects in just 24 hours. The situation has been described bluntly as "extremely bad."

A volunteer team of Bitcoin developers is conducting a large-scale, coordinated security audit. They have already confirmed that the overall state of ecosystem security is "extremely bad."

Within 24 hours, they scanned approximately 390 Bitcoin-related projects and identified a total of 4,962 security vulnerabilities, including 85 critical-level flaws and 635 high-risk ones. The vast majority of these vulnerabilities have already been verified by project teams.

"We've grown to 16 people, globally distributed, working around the clock in shifts," wrote Calle, the anonymous developer of the Cashu ecash protocol, on X. "We are conducting a large-scale ecosystem security audit of the Bitcoin codebase."

The audit team is using Moonshot's Kimi K3 model—an open-weight AI tool from China. Calle revealed that the team spends approximately $10,000 per day on computing power, with costs covered by OpenSats.

"We've been working around the clock," said Rob Hamilton, CEO of Bitcoin insurance company AnchorWatch and a member of the audit team, also on X, noting that the team has already uncovered some "critical issues."

The efficiency of this audit has been astonishing. One developer noted that, on average, a critical vulnerability has been uncovered roughly every hour. AI is simultaneously accelerating both defenders and attackers—a dynamic already hinted at in the recent Coldcard incident.

Over the past year, Bitcoin's price has already pulled back significantly, leaving the market highly sensitive to further downside. The sudden outbreak of hardware wallet security incidents has thrust the question of "is self-custody really safe" back into the spotlight.

Last week, the Coldcard Bitcoin hardware wallet suffered an exploit, with nearly 2,000 BTC (worth just over $100 million) drained from more than 5,200 addresses in a matter of days. The attackers exploited a key-generation flaw that had existed for five years.

The Coldcard team has urgently called on users to move their funds and repeatedly begged people on social media to "help spread the word."

"Please treat this as an emergency," the official Coldcard account wrote. "Migrate your funds immediately. Follow the recommendations for your device model, upgrade the device, generate a new seed, and carefully transfer your funds... The threat is ongoing."

A wallet address linked to the hackers still holds approximately $36 million in Bitcoin, the vast majority believed to be stolen funds. Since the incident came to light, multiple transfers have flowed into the address, some carrying messages via Bitcoin's OP_RETURN function.

One message read: "I wash BTC, do KYC and cash out. I take 10%." This has been interpreted as a money-laundering pitch attempting to recruit the hackers as clients. More messages were direct pleas for the return of the stolen Bitcoin.

Some on-chain analysts have pointed out that with the vulnerability now public, attention at a peak, and cutting-edge large language models accessible to nearly everyone, multiple hacker teams may already be simultaneously researching how to expand their gains. "You're racing against the clock."

Another anonymous co-owner of Bitcoin.org, Cobra, said bluntly that he has a "very bad feeling"—AI may well have already played a role in the draining of Coldcard funds.

This AI-driven vulnerability scan, combined with the earlier large-scale Coldcard theft, is pushing Bitcoin ecosystem security to a new tipping point. Developers are using AI to accelerate vulnerability discovery, while attackers may be using the same tools to accelerate exploitation. The window left for fixes and migration is being compressed.

For now, Bitcoin's price continues to fluctuate at low levels, with traders awaiting the next potential shock. And this audit, burning through $10,000 in computing power per day, may only be the beginning of a broader security review.

Safety
BTC
Developer
Welcome to Join Odaily Official Community