Community Trust ScoreVerified
Prem AI just dropped CyberScan. It’s a continuous AI security audit tool aimed squarely at Bitcoin infrastructure, and the timing isn’t subtle.
The launch comes weeks after one of the more painful hardware wallet exploits in recent memory. In late July, an attacker hit over 5,200 Coldcard hardware wallets, walking away with more than $116 million in Bitcoin. The vulnerability? A firmware regression that had apparently sat undetected for years. Nobody caught it. Not internal teams, not traditional audits, not the usual security pipeline. It just sat there, quietly, until someone found it the hard way. That kind of incident is basically the sales pitch for what Prem AI is building, and the company didn’t waste any time making that connection explicit.
ArkLabs and Breez were both in the beta.
Both firms are serious Bitcoin infrastructure players, and both used CyberScan to comb through their production code during the testing phase. That’s not a casual endorsement — production code is live, sensitive, and the last place most companies want an untested tool poking around. The fact that they let it in says something about the confidence level, or at least the urgency.
What CyberScan Actually Does
The tool runs continuously against code repositories, which is the key distinction from a traditional point-in-time audit. Standard security reviews happen on a schedule — quarterly, annually, or whenever someone remembers to book one. CyberScan doesn’t wait. It keeps scanning, preserves its scan state if interrupted, and delivers findings ranked by severity. So if a developer pushes a change at 2 a.m. that introduces a new attack vector, the system catches it without anyone having to manually kick off a review.
It integrates via API and something called the Model Context Protocol, which lets it plug into existing development workflows rather than forcing teams to build around it. Findings get formatted for platforms like GitHub, so the gap between detection and remediation shrinks. That’s the practical pitch: less time between “we found something” and “we fixed it.”
Live progress updates are part of the package. So is customizable model selection for each scan, which gives teams some flexibility depending on what they’re looking at. Prem AI also released a tailored version of its DeepSeek model specifically to support security operations across the full workflow.
And there’s an encrypted inference feature. That one matters a lot for financial services — it lets CyberScan operate autonomously without the company losing control over sensitive code. Data sovereignty is a real concern in this space, and the encrypted inference option is probably what gets CyberScan past the legal and compliance teams at bigger institutions.
Open Weights, Bitcoin First, Then Broader
Prem AI published open-weight models on Hugging Face. That’s a deliberate transparency move — it lets the broader security community examine what the models are actually doing, which is a pretty different posture from the black-box approach most enterprise security vendors take. Whether that openness builds trust or just invites scrutiny is unclear yet, but it’s consistent with the company’s stated commitment to enterprise sovereignty over AI applications.
Bitcoin was chosen first, and Prem AI is pretty direct about why. It’s a high-stakes environment. The code is largely open-source. The financial consequences of a missed vulnerability are massive and immediate. If CyberScan can hold up there, the argument for expanding it to other sectors basically makes itself.
Plans are in place to extend the tool beyond Bitcoin infrastructure. Similar vulnerabilities exist in other high-value sectors — financial services, critical infrastructure, anywhere legacy code runs alongside newer systems and nobody’s quite sure what’s lurking in the gaps. CyberScan’s ability to assess both legacy and new codebases simultaneously is probably the feature that matters most for those use cases.
The service is now in beta. Flexible pricing is available, and new users get starter credits to begin with. No hard launch date for a full commercial release was specified.
The Coldcard Incident Keeps Coming Up
It’s worth sitting with that $116 million number for a second. That wasn’t a sophisticated zero-day attack on some obscure protocol. It was a firmware regression — a bug introduced by a code change that walked back a previous fix — that nobody caught for years. Traditional audits missed it. The kind of continuous, automated review that CyberScan promises to provide might have flagged it. Maybe not. But the case for trying is hard to argue with when the alternative is a nine-figure loss.
Prem AI’s bet is that Bitcoin infrastructure operators feel the same way. ArkLabs and Breez apparently did.
Frequently Asked Questions
What companies participated in the CyberScan beta?
ArkLabs and Breez both participated in the CyberScan beta, using the tool to review their production code for vulnerabilities.
How much Bitcoin was stolen in the Coldcard exploit that preceded the launch?
An attacker exploited over 5,200 Coldcard hardware wallets in late July, stealing more than $116 million in Bitcoin through a firmware regression vulnerability.
Why It Matters
The launch of Prem AI's CyberScan underscores the critical need for enhanced security measures within the Bitcoin ecosystem, particularly in light of recent high-profile hacks that have shaken investor confidence. As vulnerabilities in hardware wallets can lead to substantial financial losses, the introduction of AI-driven security tools may signify a pivotal shift towards more proactive risk management strategies in the crypto industry. This development could influence regulatory discussions and set new standards for security practices among Bitcoin firms moving forward.





