
Original author: Forbes
Original translation: AididiaoJP, Foresight News
Bitcoin and crypto traders have yet to recover from a large-scale attack worth approximately 100 million dollars, which once ignited panic for a new round of price drops.
Since the news of the Coldcard hardware wallet attack broke, although the Bitcoin price has seen a rebound, it still hovers near recent lows. Traders are generally on edge, fearing another severe impact.
In this context, Bitcoin developers have used AI tools to uncover nearly 5,000 security vulnerabilities across nearly 400 projects in just 24 hours. The situation has been directly described as "extremely bad."
A team of Bitcoin developers, composed of volunteers, is conducting a large-scale, coordinated security audit. They have confirmed that the overall security status of the ecosystem is "extremely bad."
Within 24 hours, they scanned about 390 Bitcoin-related projects, discovering a total of 4,962 security vulnerabilities, including 85 critical vulnerabilities and 635 high-risk vulnerabilities. The vast majority of vulnerabilities have been verified by project teams.
"We have grown to 16 people, distributed globally, working around the clock," wrote Calle, an anonymous developer of the Cashu ecash protocol on X, "We are conducting a large-scale ecological security audit on the Bitcoin codebase."
The audit team used Moonshot's Kimi K3 model—an open-source weight artificial intelligence tool from China. Calle revealed that the team spends about 10,000 dollars per day on computing power, funded by OpenSats.
"We have been working day and night," said Rob Hamilton, one of the audit members and the CEO of the Bitcoin insurance company AnchorWatch, also on X, noting that the team has discovered some "critical issues."
The efficiency of this audit is astonishing. One developer noted that, on average, they can uncover a critical vulnerability approximately every hour. AI is simultaneously becoming an accelerator for both the defense and attack—this has already begun to show in the recent Coldcard incident.
Over the past year, Bitcoin's price has significantly declined, and the market is already highly sensitive to any further drops. The sudden outbreak of security incidents involving hardware wallets has brought the question of "whether self-custody is really safe" back to the forefront.
Last week, the Coldcard Bitcoin hardware wallet suffered from an exploit, with nearly 2,000 Bitcoins (worth just over 100 million dollars) drained from over 5,200 addresses in just a few days. The attackers exploited a key generation flaw that had existed for five years.
The Coldcard team has urgently called on users to transfer their funds and repeatedly requested everyone on social media to "help spread the message."
"Please treat this as an emergency," the official Coldcard account wrote, "Immediately migrate your funds. Follow the advice for your device model to upgrade, generate a new seed, and carefully transfer funds... The threat persists."
One wallet address associated with the hackers currently holds about 36 million dollars in Bitcoin, most of which is believed to be stolen. Since the incident was exposed, the address has received multiple incoming transactions, some of which included messages via Bitcoin's OP_RETURN feature.
One message stated, "I wash BTC, do KYC and cash out. I take 10%." This has been interpreted as a money laundering lure, attempting to develop hackers into clients. More messages directly beg for the return of the stolen Bitcoins.
On-chain analysts have pointed out that the vulnerabilities have been publicly disclosed, and the attention is extremely high, while cutting-edge large models are almost available for everyone, which means that multiple hacker teams may already be synchronously studying how to expand their gains. "You are racing against time."
Another anonymous co-owner of bitcoin.org, Cobra, bluntly stated that he has a "very bad feeling"—AI is very likely already involved in the event of funds being drained from Coldcard.
This AI-driven vulnerability scanning, along with the previous large-scale theft at Coldcard, is pushing the security issues of the Bitcoin ecosystem to a new critical point. Developers are using AI to accelerate the discovery of vulnerabilities, while attackers may also be using the same tools to accelerate the exploitation of those vulnerabilities. The window left for repair and migration is being compressed.
Currently, Bitcoin's price remains in a low-level fluctuation as traders wait for the next possible impact. This audit, which burns 10,000 dollars in computing power every day, may just be the beginning of a larger-scale security inspection.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。