NewsCryptoBitcoin Red Team Identifies 7,958 Security Issues Across 501 Open-Source Projects

Bitcoin Red Team Identifies 7,958 Security Issues Across 501 Open-Source Projects

Author: Crypto Adventure·

Key Takeaways

  • The Bitcoin Red Team reviewed 501 open-source Bitcoin projects and produced 7,958 findings, including 1,280 rated high or critical.
  • A 25-person team spent 108 hours on the review using manual analysis, automated testing, and AI models, especially Moonshot AI's Kimi K3.
  • The findings are a prioritized security queue rather than confirmed vulnerabilities, and maintainers must reproduce them before patches are released.
  • BTCPay Server fixed a critical flaw in version 2.4.2 after attackers exploited it to obtain LND admin macaroon credentials and steal funds.
  • More than 40 Bitcoin and digital-asset organizations signed an open letter asking AI labs to provide controlled access to frontier cybersecurity models for qualified researchers.
Bitcoin Red Team Identifies 7,958 Security Issues Across 501 Open-Source Projects

The Bitcoin Red Team has completed a large-scale security review of 501 open-source Bitcoin projects, producing 7,958 findings that include 1,280 rated high or critical severity. The effort leveraged AI to dramatically accelerate code review across wallets, Lightning Network software, and core Bitcoin infrastructure, underscoring how quickly security teams can now surface potential issues in software that underpins real funds and payment flows.

A team of 25 developers spent 108 hours on the coordinated review, combining manual analysis with automated testing harnesses and AI models. The project relied heavily on Moonshot AI's Kimi K3, alongside other models, with OpenSats funding compute costs through its dedicated Bitcoin Red Team programme.

The 7,958 entries should not be interpreted as 7,958 independently confirmed vulnerabilities. Maintainers and researchers are required to reproduce AI-generated findings, determine whether exploitable attack paths exist, and assess actual severity before any patches are released, which means the review is best understood as a prioritized security queue rather than a final vulnerability count.

Maintainers Validate Critical Findings

Bitcoin developer Calle reported that project maintainers have already validated numerous critical and high-severity reports produced during the review. The campaign expanded rapidly, growing from 4,962 findings across 390 projects on August 5 to nearly 8,000 across 501 repositories within days.

The urgency of the work intensified following Coldcard-linked Bitcoin thefts that surpassed $130 million, demonstrating how a flaw embedded in open-source firmware could go undetected for years before attackers began exploiting vulnerable wallet seeds.

Calle noted that unmaintained repositories pose a particular challenge, as AI can surface exploitable weaknesses with no active development team available to investigate or remediate them. This dynamic extends beyond Bitcoin — a risk previously highlighted when Coinbase CEO Brian Armstrong argued that AI would strengthen software security while simultaneously reducing the cost of discovering vulnerabilities.

BTCPay Server Patches Exploited Lightning Flaw

The review has already converged with an active security incident. BTCPay Server patched a critical vulnerability in version 2.4.2 that permitted an unauthenticated remote attacker to obtain LND admin macaroon credentials and potentially seize control of connected Lightning wallets.

Attackers exploited the vulnerability prior to the patch and stole funds from affected users. BTCPay subsequently committed 0.21 BTC to Craig Raw and another 0.21 BTC to the Bitcoin Red Team for responsible disclosure and analysis, while implementing stronger code-scanning and security-review procedures. Users running BTCPay Server with LND on any version preceding 2.4.2 were instructed to update immediately and rotate all affected credentials.

Coinbase and BitGo Join Call for Frontier AI Access

More than 40 Bitcoin and digital-asset organizations have signed the "Defenders Need the Frontier" open letter, urging major AI laboratories to grant qualified open-source security researchers controlled access to their most advanced cybersecurity models.

Signatories include Coinbase, Block, BitGo, Strategy, MARA, Galaxy, Trezor, Blockstream, Anchorage Digital, Brink, Chaincode Labs, and OpenSats. The coalition is requesting early model access, sufficient compute resources, secure research environments, and direct disclosure channels with AI-lab security teams.

OpenSats now operates a dedicated fund that reimburses AI compute costs and compensates researchers who responsibly disclose flaws in critical Bitcoin software. Meanwhile, BTCPay Server 2.4.2 remains the required fixed release for the exploited LND credential vulnerability.