Bitcoin Red Team Reports Nearly 5,000 Findings in Sweeping AI-Assisted Security Audit
Key Takeaways
- •Bitcoin Red Team, a 16-member volunteer group, identified 4,962 potential vulnerabilities across 390 Bitcoin-related projects within the first 29.8 hours of operation.
- •Of the total findings, 720 were classified as high- or critical-severity issues, though only 21.4% have been successfully reproduced so far.
- •The group combined AI tools with human review, reflecting a broader industry trend of using large language models to accelerate code auditing despite known false-positive challenges.
- •The security review campaign was launched shortly after the Coldcard hardware wallet hack, in which over $100 million in Bitcoin was stolen by at least 15 separate attackers.
- •The Coldcard incident highlighted persistent tensions in the Bitcoin ecosystem between open-source transparency enabling independent security review and the speed at which vulnerabilities can be responsibly addressed.

A volunteer Bitcoin security group of just 16 members has reported nearly 5,000 potential vulnerabilities after conducting a rapid AI-assisted review of projects across the Bitcoin ecosystem.
The initiative, known as Bitcoin Red Team, includes Rob Hamilton, CEO of AnchorWatch, and Bitcoin developer Calle, among others. The group has been combining AI tools with human review to scan open-source Bitcoin-related repositories for security flaws. The approach reflects a broader trend in the cybersecurity industry, where large language models are increasingly used to accelerate code auditing at a scale and speed that would be impractical for manual review alone — though automated scanning tools are also known to generate significant false-positive rates that require human triage.
"There's a lot of chaos right now in the ecosystem. We absolutely understand that many people are being bombarded with security issues right now," said Calle.
In a post on X on Wednesday, Calle stated: "We're averaging on the order of 1 critical exploit per hour per person." (Source: Calle on X)
According to Calle, during the first 29.8 hours of the team's operation, volunteers identified 4,962 potential issues across 390 projects. Of those, as many as 720 were classified as high- or critical-level issues. Thus far, 21.4% of the findings have been successfully reproduced. The relatively low reproduction rate underscores a well-known challenge in AI-assisted and automated security scanning: distinguishing genuine exploitable vulnerabilities from theoretical or lower-severity issues at high volume.
The launch of the Bitcoin security review campaign comes shortly after the Coldcard hardware wallet hack, in which over $100 million in Bitcoin was stolen. A separate report from Galaxy indicated that at least 15 attackers exploited the Coldcard vulnerability. The incident highlighted persistent tensions in the Bitcoin ecosystem between open-source transparency — which allows independent security review — and the speed at which vulnerabilities can be responsibly addressed once identified.