Artificial intelligence has a new favorite hobby, and it involves hunting down invisible flaws buried deep inside the world’s most popular digital currency. Over the last few months, a string of high-profile security breaches has proven that AI is drastically lowering the cost of uncovering vulnerabilities within Bitcoin infrastructure.
The casualties are piling up rapidly. Attackers recently siphoned roughly $114 million in cryptocurrency from Coldcard wallets. Meanwhile, developers working on Core Lightning were forced into emergency mode after AI-generated security audits flagged very real, very dangerous exploits.
The chaos didn’t stop there. White-hat hackers managed to crack Blockstream’s Liquid Network, pulling out a staggering 4,000 BTC—worth around $317 million. Fortunately, the hackers returned 3,400 BTC once the gaping holes in the code were patched.
This recent string of hacks exposes a brilliant, structural irony. The base layer of the blockchain was purposely built to be incredibly simple and secure. But as developers race to build complex, off-chain scaling layers for speed and smart contracts, they are unwittingly injecting massive vulnerabilities into Bitcoin infrastructure.
The ruthless efficiency of AI on Bitcoin infrastructure
The robots are working overtime to rip through thousands of lines of code. Last August, a small crew of 16 developers unleashed AI models on 390 different projects. The sweep generated nearly 5,000 vulnerability reports, with 85 of those initially classified as critical.
“At some point we have to admit it. AI is finding bugs that no human can find,” application developer Gregory shared in a Telegram message. An alum of Merrill Lynch and JPMorgan, Gregory co-founded CommerceBlock and helped build protocols like MainStay and Mercury Layer.
While Mercury Layer is practically defunct, its open-source skeleton still sits untouched on GitHub. According to Gregory, artificial intelligence completely alters the lifespan and threat level of aging financial software.
“If a model can wake a bug in finance C from 2006, it can probably read a statechain repo that has not moved,” he warned.
He specifically pointed out that old, neglected code could still harbor critical errors related to key-share deletion, backup transactions, shrinking locktime mechanisms, and client-side transfer checks.
“That is the new paradigm,” Gregory said. “Unused code stopped being unused the moment the cost of reading it dropped to zero.”
