A sleek device with buttons on a circuit board
AI

Liquid exploit pulls 4,000 BTC as AI-driven bug hunts hit Bitcoin’s outer layers

Coldcard’s $114M theft and a Core Lightning emergency add to a pattern of complexity-driven BTC risk.

By Elliot Marsh4 min read

White-hat hackers exploited Blockstream’s Liquid Network, withdrawing roughly 4,000 BTC ($317 million) and returning 3,400 BTC after a patch. The incident lands alongside a Coldcard wallet theft and a Core Lightning emergency, as AI-assisted security work scales vulnerability discovery across Bitcoin-adjacent code.

Liquid’s 4,000 BTC Withdrawal Puts Bitcoin Sidechain Risk Back on the Tape

Liquid is a Bitcoin-linked sidechain, meaning BTC can move into a separate chain with its own rules and operators to get faster settlement and extra features. That design concentrates risk away from Bitcoin’s base layer and into the bridge, the sidechain software, and the operational security model that keeps it running.

On Sept. 8, white-hat hackers exploited Blockstream’s Liquid Network and withdrew roughly 4,000 BTC, about $317 million. After the vulnerability was patched, 3,400 BTC was returned, leaving about 600 BTC unrecovered on the numbers disclosed so far.

This was not an isolated “Bitcoin got hacked” headline. It was a reminder that the BTC-denominated balance sheet risk often sits in the wrappers around Bitcoin: sidechains, Lightning node software, and the wallet and firmware stack traders actually use. Attackers also drained around $114 million in bitcoin from Coldcard wallets, and Core Lightning developers issued an emergency after AI-generated security reports uncovered genuine vulnerabilities.

AI Bug Hunts Scale Faster Than Bitcoin Infrastructure Can Patch

The mechanism shift is cost. AI models can read and pattern-match across large codebases quickly, turning vulnerability discovery from a bespoke craft into something closer to an industrial sweep. That changes the cadence of credible bug reports, and it compresses the time window between “nobody is looking at this repo” and “someone has a working exploit or a working patch.”

In August, 16 Bitcoin developers used AI models to sweep 390 Bitcoin projects, producing almost 5,000 findings including 85 initially rated critical. Even after triage downgrades the noisy output, the point for operators is throughput: more surface area gets reviewed, more often, and the long tail of edge cases gets cheaper to reach.

That pressure lands hardest on Bitcoin’s “complexity paradox.” Bitcoin’s main layer is intentionally simple to minimize risk, but the push for smart contracts and faster off-chain transactions has created more complex and potentially more vulnerable codebases. Layer-2 systems move transactions off the main chain, sidechains introduce distinct security assumptions, and Lightning implementations like Core Lightning add operational and software complexity at the node level.

Gregory, a bitcoin application developer who previously worked at Merrill Lynch and JPMorgan and later led CommerceBlock, framed the shift bluntly in a Telegram message: "At some point we have to admit it. AI is finding bugs that no human can find," he said.

What Traders Should Price: Complexity Premium for L2s, Wallets, and Lightning Ops

The practical repricing is a “complexity premium” on anything that holds BTC exposure behind extra code and extra operators. Liquid’s 4,000 BTC withdrawal is DeFi-scale in BTC terms, but it sits in a Bitcoin-adjacent system whose risk is not captured by base-layer metrics like mempool conditions or miner behavior.

For traders, the near-term signals are operational, not macro. Follow-up disclosure from Blockstream and Liquid on root cause, remaining unrecovered BTC (about 600 BTC), and whether additional patches or operational changes are required will matter more than broad narratives about “AI security.”

Lightning infrastructure is the other pressure point. Core Lightning already had to issue an emergency after AI-generated reports surfaced real issues, and the next tell will be whether other Lightning implementations publish coordinated advisories or similar emergency guidance as AI-generated reports proliferate.

The third monitor is the audit pipeline itself. More large-scale AI-assisted sweeps, including their scope, number of repos, and how many findings remain “critical” after triage, will act as a proxy for how fast new vulnerability discovery is accelerating. Wallet stacks belong on the same list: the Coldcard theft puts firmware and surrounding tooling back in the blast radius, and the next concrete catalyst will be security updates and postmortems tied to that incident, including whether further losses or recoveries are reported.

My Take: AI Turns Dormant Repos Into Live Attack Surface

The threshold that matters is not whether AI produces false positives. It is whether AI makes “old, quiet code” cheap enough to review that it becomes economically rational to keep probing until something real falls out.

Gregory’s framing gets to the core risk: "If a model can wake a bug in finance C from 2006, it can probably read a statechain repo that has not moved," and, more directly, "Unused code stopped being unused the moment the cost of reading it dropped to zero." If that holds, Bitcoin’s volatility and counterparty-risk catalysts will increasingly come from the operational perimeter, where complex L2s, sidechains, Lightning software, and wallet firmware concentrate BTC-denominated exposure behind code that now gets scanned at scale.

Sources