Cobo Agentic Wallet

Bitcoin Ecosystem Faces Security Vulnerabilities as BIP-110 Fork Sparks Controversy

Bitcoin blockchain reached block 961,632, triggering the controversial BIP-110 soft fork proposal with minimal community support. Developers warn of transaction replay attack risks, while AI-powered security audits uncovered nearly 5,000 vulnerabilities across the Bitcoin ecosystem in 24 hours.

Cobo Newsroom
Cobo NewsroomAug 9, 2026
Key takeaways
  • BIP-110 soft fork entered mandatory signaling phase with less than 3% miner support, far below the required 55% threshold
  • Developers warn that selling BIP-110 fork coins could trigger replay attacks, potentially causing holders to lose real bitcoin on the main chain
  • Bitcoin Red Team discovered 4,962 security vulnerabilities across approximately 390 Bitcoin projects in 24 hours, including 85 critical flaws
  • BIP-110 chain has fallen one block behind the standard Bitcoin blockchain, with mandatory signaling officially underway but lacking replay protection
  • Security audit team spends approximately $10,000 daily on computational resources, using multiple AI models to identify vulnerabilities
  • Bitcoin price remains near recent lows amid heightened market sensitivity to further security incidents

News illustration

Summary

Bitcoin blockchain reached block 961,632, triggering the controversial BIP-110 soft fork proposal with minimal community support. Developers warn of transaction replay attack risks, while AI-powered security audits uncovered nearly 5,000 vulnerabilities across the Bitcoin ecosystem in 24 hours.

BIP-110 Fork Activation Triggers Technical Controversy

The Bitcoin blockchain reached block height 961,632 on August 7, marking the official start of the mandatory signaling period for the controversial BIP-110 soft fork proposal. Designed to temporarily curb non-financial data from being embedded on the Bitcoin network, the proposal's activation process has sparked widespread concern and debate within the community.

According to on-chain data, miner support for BIP-110 stood at approximately 2.5% when the proposal entered its signaling phase, falling dramatically short of the 55% activation threshold required. Despite this lack of consensus, proponents continue to push BIP-110 as a user-activated soft fork (UASF), which relies on node operators rather than miners to enforce rule changes. This approach requires users to update their node software to reject blocks from any miner that fails to signal support for BIP-110.

Notably, several prominent figures in the Bitcoin space have publicly voiced opposition to the proposal. Industry leaders including Strategy chairman Michael Saylor and Blockstream CEO Adam Back have expressed reservations, further highlighting the community's fundamental disagreement over the network upgrade path.

As of the latest update, the BIP-110 chain has fallen one block behind the standard Bitcoin blockchain, with mandatory signaling officially underway. This technical divergence not only reflects fundamental disagreements within the Bitcoin community regarding the network's intended use cases but also exposes the complexity of decentralized governance mechanisms when facing major technical decisions.

The situation underscores a broader challenge in blockchain governance: how to balance innovation with consensus, and how to manage technical upgrades when stakeholder interests diverge significantly.

Transaction Replay Attack Risks Raise Security Concerns

Bitcoin developers have issued warnings that if the BIP-110 fork materializes, holders could face serious asset loss risks when handling fork coins. The core issue lies in the transaction replay attack mechanism.

When a blockchain undergoes a fork, users end up holding identical balances on both chains. This may appear as free money, tempting some users to attempt selling the fork coins for profit. However, because both chains initially accept identical transaction signatures, a signed transaction intended to send fork coins can also be broadcast and executed on the Bitcoin main chain.

This means that if a user signs a transaction to sell fork coins, the buyer can replay the same transaction on the Bitcoin mainnet, thereby obtaining the user's real bitcoin on the main chain. Developers emphasize that until at least early September, the BIP-110 fork lacks built-in replay protection mechanisms. Therefore, for non-expert users, the safest course of action during the potential split is to avoid moving any coins.

This technical risk presents new challenges for institutional-grade digital asset custody services. During fork events, safely handling client assets, identifying and isolating balances on different chains, and preventing replay attacks all require professional technical solutions and operational procedures. For users of multi-signature wallets or custody services, maintaining caution during fork periods and following service provider guidance is critical.

The replay attack vulnerability also highlights the importance of technical due diligence in the digital asset space. Professional service providers must develop comprehensive fork handling procedures, implement transaction isolation mechanisms, and maintain clear communication protocols with clients during network upgrade events.

AI-Driven Security Audit Reveals Ecosystem Vulnerabilities

While the BIP-110 fork controversy continues to unfold, the security posture of the Bitcoin ecosystem has come under unprecedented scrutiny. A volunteer team of Bitcoin developers known as Bitcoin Red Team is conducting a large-scale, coordinated security audit, and their findings are alarming.

In just 24 hours, the team used AI tools to scan approximately 390 Bitcoin-related projects, discovering a total of 4,962 security vulnerabilities, including 85 critical flaws and 635 high-severity issues. The vast majority of these vulnerabilities have been verified by project teams. To date, the team has scanned approximately 150 Bitcoin code repositories and disclosed over a dozen vulnerabilities.

Calle, an anonymous developer of the Cashu ecash protocol, revealed that the audit team has grown to 16 people distributed globally, working around the clock in shifts. The team employs Moonshot's Kimi K3 model alongside OpenAI's GPT, Anthropic's Claude, and other AI tools. Daily computational expenditure reaches approximately $10,000, funded by OpenSats.

Rob Hamilton, CEO of Bitcoin insurance company AnchorWatch, stated that the team has spent approximately $20,000 on various AI services to date. He noted that the team has discovered some critical issues, with an average rate of approximately one critical vulnerability identified per hour.

The audit's efficiency is remarkable, but it also reveals a disturbing reality: AI is simultaneously becoming an accelerator for both defenders and attackers. While developers use AI to accelerate vulnerability discovery, potential attackers may employ the same tools to accelerate exploitation. The window for remediation and migration is being compressed.

The Bitcoin Red Team is developing an open-source AI platform for auditing Bitcoin software, covering wallets, cryptographic libraries, infrastructure, and other projects. This initiative represents a proactive approach to security in an era where AI-powered tools are democratizing both offensive and defensive capabilities in cybersecurity.

Hardware Wallet Security Incident Highlights Self-Custody Risks

Concerns about Bitcoin ecosystem security are not unfounded. Recently, the Coldcard Bitcoin hardware wallet suffered an exploit that resulted in nearly 2,000 bitcoin (worth just over $100 million) being drained from more than 5,200 addresses within a few days. Attackers exploited a key generation flaw that had existed for five years.

The Coldcard team issued urgent calls for users to migrate funds and repeatedly requested on social media that people help spread the word. The official account stated: Treat this as an emergency. Migrate your funds immediately. Follow the recommendations for your device model, upgrade your device, generate a new seed, and carefully transfer funds. The threat is ongoing.

A wallet address associated with the hackers currently holds approximately $36 million in bitcoin, the vast majority believed to be stolen proceeds. Since the incident became public, the address has received multiple incoming transactions, some of which included messages via Bitcoin's OP_RETURN function, including money laundering solicitations and pleas for return of stolen funds.

On-chain analysts noted that with the vulnerability now public and widely known, and frontier AI models accessible to nearly everyone, multiple hacker teams may already be researching how to expand the attack. Cobra, an anonymous co-owner of bitcoin.org, stated bluntly that he has a very bad feeling that AI likely played a role in the Coldcard fund drainage incident.

Furthermore, reports indicate that over $3 million has been stolen, with the same attacker running phishing campaigns targeting Ledger users, demonstrating that security threats facing the hardware wallet ecosystem are expanding.

These incidents raise fundamental questions about self-custody security models and the adequacy of current hardware wallet designs in an era of AI-accelerated threat discovery and exploitation.

Market Response and Industry Implications

Against the backdrop of frequent security incidents, Bitcoin's price continues to fluctuate near recent lows. Over the past year, Bitcoin's price has fallen significantly, and the market was already highly sensitive to further declines. The sudden emergence of hardware wallet security incidents has brought the question of whether self-custody is truly safe back to the forefront.

Traders remain on edge, wary of another sharp shock. Since news of the Coldcard breach first emerged, Bitcoin's price has rebounded somewhat but continues to hover near recent lows, with market confidence not yet fully restored.

This series of events offers profound warnings for the entire digital asset industry. First, technical upgrades require sufficient community consensus; forcefully pushing fork proposals that lack support may bring unexpected risks. Second, with the proliferation of AI technology, both the discovery and exploitation of security vulnerabilities are accelerating, requiring project teams to establish faster response mechanisms.

For institutional investors and professional service providers, these events underscore the importance of professional security audits, multi-layered risk controls, and emergency response plans. When handling client assets, heightened vigilance toward potential technical risks is necessary, along with comprehensive fork handling procedures and replay attack protection mechanisms.

The Bitcoin Red Team's open-source AI platform is expanding its audit scope to cover wallets, cryptographic libraries, infrastructure, and other projects. This audit effort, burning through $10,000 in computational resources daily, may be only the beginning of a broader security review. The Bitcoin ecosystem is undergoing an AI-driven security stress test, and finding the balance between technological innovation and security assurance will be a long-term challenge the entire industry must collectively address.

As the digital asset industry matures, the intersection of decentralized governance, technical security, and AI-powered tools presents both opportunities and risks. The events surrounding BIP-110 and recent security breaches serve as reminders that technological advancement must be accompanied by robust security practices, clear governance processes, and informed user education. The path forward requires collaboration among developers, service providers, and users to build a more resilient and secure ecosystem.

Source: link

REGULATIONSAI

About Cobo

Cobo is an institutional digital asset infrastructure provider founded in 2017. The Cobo Agentic Wallet extends Cobo's MPC custody platform to autonomous onchain agents.

Press inquiries: [email protected] · Media kit, executive bios, and additional materials available on request.
Agentic Economy by Cobo

Get this in your inbox every Friday.

The weekly newsletter from the Cobo team — unpacking the most consequential stories in crypto, AI & payments through the lens of institutional custody.