Back in May, we announced Project Loupe, an AI-powered vulnerability scanner for bitcoin open-source projects. As part of the trial phase, we onboarded a cohort of seven projects (Bitcoin Core, rust-bitcoin, LDK, BDK, CDK, SRI, and bitcoinj) and started scanning 24 repositories for security-relevant issues and vulnerabilities. Now, after two months, we’re wrapping up the trial run and can share some results.
To help us improve the tool for future cohorts, we collected feedback from all participating projects regarding the utility of the reports, their signal-to-noise ratio, and the number of actionable security issues identified.
In total, we reported 643 findings, of which 354 (55%) were deemed directly actionable. However, only 51 (8%) of findings were considered security-relevant, and 10 (2%) were deemed high severity or above. More than 70 reported issues have already been fixed as of today, and projects indicate they still plan to address more than 100 of the remaining issues in a timely fashion.
Previous #1489096