Evaluating Security Risks in Leading Bitcoin Layer 2 Architectures
Rob Hamilton, CEO of AnchorWatch, disclosed on X that a volunteer Bitcoin red team has scanned 150 repositories using frontier AI models and is identifying critical exploits at a rate of roughly one per hour per reviewer, at a daily burn of $10,000.
Caleb North·updated August 14, 2026

The scope covers wallets, cryptographic libraries, and Bitcoin-adjacent infrastructure. Against that backdrop, the four L2 architectures drawing measurable liquidity in August 2026 — Stacks, Bitlayer, Citrea, and Rootstock — warrant a forensic pass, not a celebratory one. "Bitcoin L2" is not a single security class. It is a label applied to rollups, sidechains, and Bitcoin-linked networks with radically different trust assumptions.
The Threat Surface Has Shifted
The red team uses Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable and Opus, and Z.ai's GLM 5.2, according to Hamilton. Pseudonymous developer Calle stated the initiative targets wallets, cryptographic libraries, and infrastructure projects, with critical vulnerabilities reported to several projects inside a 12-hour window. The disclosure follows AI-assisted discovery of a four-year-old Zcash flaw permitting unlimited counterfeit ZEC, the Coldcard wallet compromise attributed to AI-assisted attackers, and the Boltz bridge suspension after AI-driven exploitation outpaced patches. Audit velocity now matches or exceeds patching velocity on portions of the Bitcoin stack. Any L2 claiming production readiness inherits this threat model — bridge, sequencer, and smart contracts included.
Four Architectures, Four Risk Profiles
Stacks operates on Proof of Transfer with Clarity smart contracts and settles to Bitcoin finality. sBTC was reported at approximately $545 million TVL in Q1 2026. DeFi protocols on the network held roughly $121 million, with Zest Protocol accounting for $75.9 million. Q2 brought a record 110 million STX in ecosystem TVL, and BitFlow surpassed $5 billion in cumulative transaction value. Maturity is real. So is the attack surface: every peg-in, peg-out, and Clarity contract is in the red team's review queue.
Bitlayer builds around BitVM to reduce trust assumptions for BTC entering programmable environments. YBTC Family TVL reached nearly $100 million in March 2026, alongside approximately $98.54 million in transaction volume and over 10,000 monthly active users. The BTCFi platform reports over $52 million deployed in yield strategies with advertised yields ranging from roughly 1% to 7.4%. BitVM's optimistic execution introduces a challenge window. That window is the attack vector.
Citrea runs as an EVM-compatible zk-rollup using Bitcoin for both settlement and data availability. Mainnet went live January 2026 with two-second blocks and cBTC as the gas asset. Full nodes can reconstruct rollup state from data published to Bitcoin rather than depending on an external DA committee. This is the cleanest trust model in the set. It concentrates failure risk in the prover and the verifier contract.
Rootstock remains operational under merged mining, tying its security model to Bitcoin miners. Block height exceeded 9.1 million by late July. RBTC serves as gas in an EVM environment. The longest operating history does not eliminate merge-mining centralization risk. It documents it.
Pre-Deployment Checklist
- Bridge backing: confirm 1:1 with on-chain proof, not custodian attestation.
- Sequencer control: single-sequencer models are censorship vectors. Locate the escape hatch.
- Validator threshold: count the honest-party assumption. Write it down.
- Verifier contract: for zk-rollups, this is the highest-value target. Audit it first.
- Liquidity snapshot: TVL figures above are point-in-time. Pull current state from the explorer before deployment.
The "Bitcoin L2" label is a marketing claim, not a security guarantee. It demands the same strategic contract reviews applied in any financially constrained domain, where terms drafted under pressure rarely survive contact with execution.