Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Bitcoin Red Team Identifies Nearly 5,000 Security Vulnerabilities in 30-Hour AI-Assisted Audit of Open-Source Projects
00

Bitcoin Red Team Identifies Nearly 5,000 Security Vulnerabilities in 30-Hour AI-Assisted Audit of Open-Source Projects

Aug 6, 2026

In response to a devastating Coldcard hardware wallet vulnerability that caused over $100 million in losses, the volunteer Bitcoin Red Team launched a rapid, AI-assisted security audit. Comprising 16 researchers led by developer Calle and AnchorWatch CEO Rob Hamilton, the team scanned 390 open-source Bitcoin repositories in under 30 hours. The effort, funded by a $40,000 grant from OpenSats, flagged 4,962 potential vulnerabilities, including 85 critical and 635 high-severity issues. While only 21.4% of findings have been reproduced, the massive influx of reports has flooded and overwhelmed project maintainers.

Bitcoin Red Team audit

  • ▪The Bitcoin Red Team logged 4,962 total security findings during an audit sprint spanning August 4 to 5, 2026.
  • ▪The Bitcoin Red Team's audit sprint was completed in a window reported variously as 27.5 hours, 29.8 hours, or approximately 30 hours.
  • ▪The Bitcoin Red Team, a volunteer security group of 16 researchers, conducted a rapid, large-scale security audit of 390 open-source Bitcoin projects.
  • ▪The Bitcoin Red Team's audit sprint was funded by OpenSats, a nonprofit that contributed nearly $40,000 to cover AI token expenses.
  • ▪The Bitcoin Red Team's audit was led by pseudonymous Cashu creator Calle and AnchorWatch CEO Rob Hamilton.

Coldcard vulnerability trigger

  • ▪The Bitcoin Red Team's audit was triggered by a catastrophic firmware vulnerability in Coldcard hardware wallets that compromised seed generation randomness.
  • ▪The Coldcard hardware wallet vulnerability resulted in the theft of over $100 million in Bitcoin, with specific estimates ranging from $114 million to $130 million.
  • ▪Coinkite, the manufacturer of Coldcard, released fixed firmware and advised affected users to generate new recovery seeds and transfer their funds.

Security findings severity breakdown

  • ▪Only 21.4% of the Bitcoin Red Team's 4,962 findings had been successfully reproduced as exploitable at the time of the initial updates.
  • ▪Privacy and coinjoin tools returned the highest proportion of high-or-critical findings at 24%, followed by swaps and exchanges at 21%.
  • ▪Of the 4,962 findings, the Bitcoin Red Team classified 85 as critical and 635 as high-severity, totaling 720 high- or critical-level issues.

AI-driven security methodology

  • ▪The Bitcoin Red Team built a custom automated harness, which at one point comprised 171,599 lines of code, to identify and test critical Bitcoin libraries.
  • ▪The Bitcoin Red Team utilized AI-driven analysis tools, including models like Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, to scan codebases.
  • ▪The Bitcoin Red Team plans to open-source their custom security harness to allow Bitcoin companies to run audits against their own code.

Responsible disclosure process

  • ▪The Bitcoin Red Team followed a responsible disclosure process, reproducing critical issues locally before privately informing project maintainers.
  • ▪Only 19 projects, representing under 5% of the 390 reviewed, had findings disclosed upstream to maintainers in the initial phase of the campaign.
  • ▪The Bitcoin Red Team apologized to project maintainers for the added stress and chaos caused by the sudden flood of security reports.

9 sources

Decrypt
Bitcoin AI Security Audit Files 4,962 Findings Across 390 Projects - Decrypt
View source article
Bitcoinmagazine
4,962 Vulnerabilities In 27.5 Hours: Bitcoin Red Team’s AI Blitz Is Rewriting Open-Source Security
View source article
Kucoin
Bitcoin Red Team Discovers 4,962 Security Issues in 27.5 Hours During Open-Source Audit | KuCoin
View source article
Pluang
Bitcoin Red Team spots nearly 5,000 potential s... | Pluang
View source article
Gncrypto
Bitcoin Red Team Finds Nearly 5,000 Issues in 30-Hour Audit
View source article

Featured stories

View more in Bitcoin security & risks

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

OpenAI and Synopsys partner to develop AI model for chip design

Sep 30, 2026 · 3 sources

DeepSeek releases software tools for Huawei AI chips to challenge Nvidia

Sep 30, 2026 · 4 sources

OpenAI launches Dots, always-on AI agents that work across 4,000+ apps

Sep 29, 2026 · 14 sources

Story comments

Loading comments…

Topics

Bitcoin security & risksAI securityOpen source AI ecosystems & communitiesBitcoin wallets & custodyAI tools & products

Featured stories

View more in Bitcoin security & risks

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

OpenAI and Synopsys partner to develop AI model for chip design

Sep 30, 2026 · 3 sources

DeepSeek releases software tools for Huawei AI chips to challenge Nvidia

Sep 30, 2026 · 4 sources

OpenAI launches Dots, always-on AI agents that work across 4,000+ apps

Sep 29, 2026 · 14 sources