Bitcoin Red Team Scans 390 Projects, Finds Over 1,000 Critical and High-Severity Vulnerabilities Using AI
Key Takeaways
- •The Bitcoin Red Team scanned approximately 390 open-source Bitcoin projects in a 30-hour sprint, producing 4,962 security findings that included 85 critical and 635 high-severity vulnerabilities.
- •The initiative was launched in direct response to a Coldcard hardware wallet firmware vulnerability in its random-number generator that reportedly caused losses between $70 million and $114 million.
- •The campaign was organized by Bitcoin developer Calle and AnchorWatch CEO Rob Hamilton, with funding from OpenSats bringing total expenditures to over $40,000.
- •Only about 21.4% of the reported findings had been independently reproduced at the time of reporting, meaning a substantial portion will require further manual validation before being confirmed as actionable vulnerabilities.
- •The team plans to open-source its custom-built AI security harness, which could enable similar community-driven audits across other open-source ecosystems beyond Bitcoin.

A grassroots security initiative known as the Bitcoin Red Team has completed a rapid audit sprint that scanned approximately 390 open-source Bitcoin-related projects, producing 4,962 security findings. The results include 85 critical and 635 high-severity vulnerabilities, according to the team.
The 30-hour effort, carried out by 16 volunteers, was organized in direct response to a firmware vulnerability in Coldcard hardware wallets. That flaw, located in the device's random-number generator, was estimated to have caused losses between $70 million and $114 million in stolen Bitcoin. The vulnerability meant that the component responsible for generating private keys was compromised, potentially allowing attackers to predict those keys. Coldcard wallets are widely used among Bitcoin holders seeking self-custody, and the incident reinforced long-standing concerns about single-vendor hardware security in an ecosystem where users are their own final line of defense against loss.
Origin and Organization
The scale of the Coldcard losses drew the attention of Calle, a well-known Bitcoin developer, and Rob Hamilton, CEO of AnchorWatch. Together, they organized the Red Team campaign in late July and early August 2026, assembling volunteers and securing funding from OpenSats, an open-source Bitcoin grant organization. Total expenditures for the initiative exceeded $40,000.
AI-Powered Scanning
The team utilized open-weight AI models to accelerate the scanning process. The toolkit included Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, each deployed through a custom-built security harness designed for rapid vulnerability discovery. The team stated that it plans to open-source the harness, which could enable similar community-driven audits across other open-source ecosystems beyond Bitcoin.
Across the 16 volunteers working over the roughly 30-hour sprint, the team averaged approximately 2.31 high or critical findings per person-hour.
Verification and Responsible Disclosure
At the time of reporting, only about 21.4% of the findings had been independently reproduced. The team filed their results directly with project maintainers, establishing a pipeline for responsible disclosure. The relatively low reproduction rate at this stage reflects the inherent tension between speed and certainty when using AI-assisted scanning at scale, and means that a substantial portion of the reported findings will require further manual validation before they can be confirmed as actionable vulnerabilities.
The Coldcard exploit that prompted the initiative underscored how a single firmware bug in a device marketed as a leading self-custody solution could result in substantial financial losses. The Bitcoin Red Team's findings highlight the role of community-driven, AI-assisted security audits in identifying vulnerabilities across the open-source Bitcoin ecosystem, while the open-source harness and disclosure pipeline the team built may serve as a reusable model for future coordinated security efforts.