Decrypt and Unchained both cover the volunteer Bitcoin Red Team's AI security audit and quote the same pseudonymous coordinator, Calle, but give conflicting numbers for repositories scanned, findings disclosed, and the rate of critical bugs found.
What all sources agree on
- The initiative is a volunteer 'Bitcoin red team' using AI models to audit Bitcoin wallets, cryptographic libraries, and infrastructure.
- Calle, the pseudonymous developer behind the Cashu ecash protocol, is coordinating or speaking for the campaign.
- Rob Hamilton is involved in building the automated system.
- The effort is linked to broader AI-assisted security discoveries in crypto, including the Zcash counterfeit-minting bug found earlier in the year.
Where the reports disagree
1Number of projects/repositories scanned and findings disclosed
The team filed 4,962 security findings across 390 projects, including 85 critical and 635 high-severity issues, according to “Calle,” the pseudonymous developer behind the Cashu ecash protocol who is coordinating the campaign.
The initiative says it has scanned about 150 Bitcoin repositories and made more than a dozen vulnerability disclosures.
What would settle it: A public disclosure log or repository list published by the Bitcoin Red Team itself.
2Rate of critical/high findings per person per hour
The group, which calls itself the Bitcoin Red Team, at the roughly 27-hour mark was averaging 2.31 high or critical findings per person per hour, Calle said, adding that the rate was climbing as the team’s automated harnesses improved.
"We're averaging on the order of one critical exploit per hour per person,” Calle wrote on X.
What would settle it: Calle's original X posts or the Bitcoin Red Team's own published statistics, timestamped.
What to make of it
Treat the existence of the volunteer AI-driven Bitcoin security audit and Calle's involvement as established, but do not rely on any single figure for repositories scanned, total findings, or the findings-per-hour rate until the team publishes its own consolidated disclosure log.
Treat the existence of the volunteer AI-driven Bitcoin security audit and Calle's involvement as established, but do not rely on any single figure for repositories scanned, total findings, or the findings-per-hour rate until the team publishes its own consolidated disclosure log.