Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit
Key Takeaways
- •The Bitcoin Red Team has audited more than 390 open source repositories and reported 4,962 findings after 27.5 hours of work.
- •The team says it has identified 85 critical issues and 635 high-severity issues so far.
- •More than $40,000 in AI token costs have been covered by OpenSats, a nonprofit that funds open source Bitcoin development.
- •The Red Team is using models including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, and it has gained access to OpenAI and likely Anthropic models.
- •Rob Hamilton said the team plans to open source its custom harness so Bitcoin companies can use it against closed-source code.

Bitcoin Magazine reports that the recent catastrophic vulnerability in Coldcard hardware wallets, which was exploited for more than $100 million, has prompted members of the Bitcoin community to intensify efforts to prevent similar critical bugs in open source software used across the industry.
PSA: Users of Coldcard wallets who have not moved their bitcoin to new seeds generated in secure firmware are still at risk. It may not be too late to act; see the advisory on the matter.
Led by Calle, a software engineer, avid vibe coder, and creator of the Android version of Bitchat, and Rob Hamilton, the CEO of Anchorwatch, a Bitcoin self-custody insurance company, the Bitcoin Red Team has secured funding and spent more than $40,000 in AI tokens to audit more than 390 open source repositories across Bitcoin. The effort reflects how quickly security incidents in one widely used product can ripple through the broader ecosystem, especially where software libraries and tooling are reused across multiple projects.
Known informally as the “Bitcoin Red Team,” with memes circulating about Rob Hamilton and Calle becoming the CEO and CTO of Bitcoin, the AI-driven security audit is drawing attention across the industry. Just days after ongoing thefts of bitcoin from MK3+ Coldcards tied to an RNG bug, Boltz exchange said it would pause operations to catch up with AI-driven hacking attempts.
“27.5 hours in, we’ve filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We’re at 2.31 h+c findings per person per hour,” Calle said in the latest update on the Red Team’s cybersecurity work.
The security review is using models including Kimi K3, GPT Sol, Fable, Opus and GLM5.2, described as some of the most expensive and cutting-edge models available. At first, access to OpenAI and Anthropic models was limited, which led to greater reliance on Chinese open-source models, a situation that many in the industry viewed with concern and as a possible warning sign for U.S. AI dominance. As the Red Team gained influence after last week’s Coldcard hack, connections were established and confirmed with OpenAI, giving the group access to GPT Sol. Hamilton’s mention of Fable in his August 4 tweet suggests access to Anthropic was also established.
Expenses, last tallied at more than $40,000, have been covered by OpenSats, a nonprofit 501(c)(3) organization that funds open source Bitcoin development projects. The Bitcoin Red Team does not currently have a website or GitHub repository to link to, but the group includes many people in the Bitcoin industry. Individuals publicly thanked for their support include, but are not limited to, danielabrozzoni, lylepratt, stutxo, benthecarman, and thesimplekid.
Hamilton said the team has built a custom harness that is evolving quickly. At one point, it consisted of 171,599 lines of code. The harness is designed to identify and test critical Bitcoin software libraries and other high-load-bearing code, identify and document vulnerabilities, reproduce them, and package the verified data into useful reports for responsible disclosure to engineers in the industry. Hamilton also said the Red Team intends to open source the harness so Bitcoin companies can run it against their closed-source code.
The Red Team is actively contacting relevant open source projects where it discovers critical vulnerabilities, which has led to a broad sense of dread among engineers when they receive direct messages from Hamilton or Calle, as shown in humorous screenshots shared on social media. https://x.com/callebtc/status/2085035257477190080
Among the key insights the Red Team has shared publicly during this AI-driven security effort, Hamilton said that engineers with specific subject-matter expertise can sometimes help produce high-value results from the harness, even when the system might otherwise “smell out something is wrong” but still lack niche context. The point underscores the value of human intelligence and experience working alongside AI to identify critical vulnerabilities efficiently.
Hamilton also closed a multi-day Red Team effort after the Coldcard hack with personal remarks. He said the vulnerability in Coldcard random number generators and the resulting exploitation by hackers was a “spiritual attack” on Bitcoin and the industry’s self-custody ethos, adding, “I mean that in the literal sense of the words”. After expressing grief for the losses suffered by many Bitcoiners in what he described as a historic hack, Hamilton ended with a note of resolve: “While things are not easy right now. I have the highest conviction ever in my life that the idea and technology of Bitcoin is worth fighting for. To that end. There is no Bitcoin without self-custody. This is non-negotiable.”
This article first appeared on Bitcoin Magazine and is written by Juan Galt.