On August 9, a voluntary security team deployed a suite of advanced AI models—Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable, Opus, and Z.ai's GLM 5.2—to scan approximately 150 Bitcoin core code repositories. The result: over a dozen vulnerabilities across wallets, cryptographic libraries, and infrastructure projects. One team member disclosed that each researcher could identify roughly one critical vulnerability per hour. In the past 12 hours, reports were submitted to multiple projects, though specifics remain undisclosed.
This is not a story about attacker advantage. It is a story about structural risk—the kind that erodes trust not through malice, but through volume.
Context: The Open-Source Security Paradox
Bitcoin's security model relies on the assumption that the code is audited by a sufficient number of eyes. But that assumption is aging. The Bitcoin core ecosystem spans thousands of dependencies, each with its own attack surface. Voluntary security teams have historically operated with limited bandwidth, manually reviewing commits. The introduction of LLMs (Large Language Models) changes the unit economics of vulnerability discovery.
Based on my experience auditing ICO whitepapers in 2017, I recall that the biggest bottleneck was not detection—it was triage. Teams would find a flaw, but the time to confirm exploitability, write a proof-of-concept, and coordinate disclosure often delayed patches by weeks. AI collapses that timeline. The team in question used four different models to cross-validate findings, generating documentation automatically. The density of output is unprecedented.
Recent incidents involving Coldcard and Boltz further illustrate the shift. Coldcard, a popular hardware wallet, faced a vulnerability that could have been exploited by a remote attacker if the AI-assisted analysis had been weaponized. Boltz, a Lightning Network-based swap service, experienced a similar close call. Both cases underscore that AI is no longer a theoretical tool—it is now a standard part of the security researcher's toolkit, and by extension, the attacker's.

Core: The Liquidity of Vulnerability Lifecycles
Vulnerability discovery is a liquidity event. Each flaw represents a potential drain on the protocol's trust capital. When a vulnerability is found, the clock starts ticking. The window between discovery, disclosure, and patch is the most volatile period for any crypto project. In traditional finance, zero-day exploits are rarer and more expensive. In crypto, the open-source nature means that anyone can fork the code, scan it, and exploit it.
AI accelerates this cycle. A manual auditor might find one critical vulnerability per week. The reported rate of one per hour per researcher is a 50x improvement. But the key insight is not the speed of discovery—it is the asymmetry of response. The defenders must patch, test, and deploy across a distributed network of nodes. The attacker only needs to find one unpatched node.
Code does not lie, but incentives often do. The voluntary security team's motives are pure—they are protecting the ecosystem. But the same technology used by a state-sponsored actor or a rogue miner could shift the balance. The cost of launching a vulnerability mining campaign just dropped. The marginal cost of finding a new zero-day is now essentially the cost of compute time.
Consider the implications for Bitcoin core's development process. The current review cycle relies on maintainers manually approving pull requests. When AI can generate patches and even suggest fixes, the volume of contributions will increase. But so will the noise. The signal-to-noise ratio becomes a governance problem. How do you trust a patch that was co-authored by an LLM? The code may be syntactically correct, but the logic may contain hidden backdoors.
From my 2020 DeFi Summer analysis, I learned that liquidity subsidies mask underlying fragility. Similarly, AI-assisted vulnerability discovery may mask the real fragility of the open-source security model. The more vulnerabilities found, the more patches needed, and the more maintenance burden on core developers. The system becomes dependent on an ever-growing number of volunteers to review and apply fixes. That is not sustainable.
Contrarian: The Decoupling Thesis—AI Widens the Defense Gap
The common narrative is that AI will democratize security, leveling the playing field between white hats and black hats. I argue the opposite. AI will widen the gap.
Why? Because the defender's problem is harder. An attacker only needs to find one exploit that works. A defender must ensure that no exploit works. For a protocol like Bitcoin, with billions in value, the defender's surface area is enormous. AI can scan repos at scale, but the attacker can also scan for the same vulnerabilities. The difference is that the attacker can exploit immediately, while the defender must coordinate a global patch.
Stability is a feature, not a market condition. Bitcoin's stability comes from its conservative upgrade process. But that process is slow by design. AI introduces a new variable: the speed of vulnerability discovery now outpaces the speed of patch deployment. The traditional assumption that vulnerabilities are rare and take time to find is broken. The new reality is that vulnerabilities are abundant and cheap to find.
This is not a flaw in Bitcoin. It is a feature of the open-source model that we must now account for. The decoupling thesis states that the security of crypto assets will no longer be correlated with their code quality alone. It will be correlated with the speed of response and the depth of the development community. Those with larger, more responsive teams will survive. Smaller projects will become vulnerable to AI-driven attacks.
Yield without basis is just delayed liquidation. The basis in this case is the trust that the code is secure. AI is slowly eroding that basis. The market has not priced this risk yet. The current sideways market is masking the structural shift. But when the first major AI-discovered vulnerability is exploited in the wild, the liquidity will drain from the affected projects faster than any manual audit could prevent.
Takeaway: Positioning for the AI Security Cycle
The cycle is shifting. The next bull run will not be driven by retail FOMO. It will be driven by institutional capital that demands proof of security. The protocols that invest in AI-assisted auditing now will have a competitive advantage. The ones that rely on legacy manual processes will be left behind.
Liquidity is the only truth in a vacuum of trust. The vacuum is filling with AI-generated vulnerabilities. The market will eventually reward those who can demonstrate real-time security monitoring and rapid patch deployment. For investors, the question is not whether your favorite L1 has good code. The question is:
How fast can your protocol's security team react when an AI model finds a flaw in the next hour?
If the answer is not immediate, the position is already underwater.