Sixteen volunteers scanned approximately 390 open-source Bitcoin-related projects in just 30 hours, uncovering 4,962 security findings including 85 critical and 635 high-severity vulnerabilities. This initiative, funded at over $40,000 by the OpenSats organization, was triggered by the exploitation of a firmware vulnerability in Coldcard hardware wallets that caused estimated losses of $70 million to $114 million in Bitcoin. The team employed open-weight AI models including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, achieving a rate of approximately 2.31 high or critical findings per person-hour. Roughly 21.4% of findings had been independently reproduced at the time of reporting, and results were delivered to project maintainers through a responsible disclosure pipeline.
Source: Read the original article

