Gold Bitcoin token standing upright in close-up against a dark background with warm lighting.
TECHNOLOGY

Bitcoin Red Team Flags 4,962 Issues

Image credit: Unsplash

Bitcoin Red Team has logged 4,962 potential security findings across 390 Bitcoin-related open-source projects during an AI-assisted review completed in less than 30 hours.

The 16-person volunteer group gave 85 findings preliminary critical ratings and classified another 635 as high severity. Only 21.4% of the full total had been reproduced in the latest update, meaning most findings still require verification.

720 Findings Receive Preliminary High or Critical Ratings 

Bitcoin developer Calle and AnchorWatch Chief Executive Rob Hamilton helped organize the effort following the disclosure of a random-number generation flaw affecting Coldcard hardware wallets.

The team used AI tools alongside human review to examine open-source projects across the Bitcoin ecosystem, including wallets, exchanges, libraries and other infrastructure. The initiative does not indicate that Bitcoin’s core protocol has been compromised.

Calle initially reported that the group had logged 4,962 findings across 390 projects within 27.5 hours. He said the team was producing 2.31 high or critical findings per researcher per hour. A later update placed the review at 29.8 hours, retained the same total and reported that 21.4% of findings had been reproduced.

Only 21.4% of Findings Have Been Reproduced 

The raw total includes potential bugs that may prove to be false positives, duplicates, or issues with limited practical impact. Preliminary severity labels do not establish that a finding can be exploited under real-world conditions.

Reproduction allows reviewers to confirm the reported behavior, determine its practical effect and reassess the initial severity rating. The 720 high and critical classifications should therefore not be treated as 720 confirmed vulnerabilities.

The latest reproduction rate indicates that most of the audit queue remains under review. Further verification will determine how many findings require action from project maintainers.

Coldcard Seed Flaw Prompted the 30-Hour Security Review 

The review began days after Coinkite warned that affected Coldcard firmware had generated recovery seeds with less entropy than intended.

The flaw caused impacted devices to use a deterministic software fallback instead of the intended hardware random-number generator. Coinkite released fixed firmware for affected models, but updates cannot strengthen seeds created under vulnerable versions.

Bitcoin Red Team’s reported totals remain preliminary as reproduction continues. The next material update will be how many findings survive verification and retain their high or critical severity classifications.

More For You

Texas Pauses Data Center Approvals
REGULATION

Texas Pauses Data Center Approvals

Texas has paused approvals for new data centers, delaying projects as officials review infrastructure,…

Aug 5, 2026 2 min read
Explore More News