TLDR
- Bitcoin Red Team filed 4,962 security findings across 390 Bitcoin projects in around 30 hours
- 720 findings were rated high or critical, but only 147 have reached the developers who need to fix them
- The security sweep was triggered by the Coldcard hardware wallet hack, which saw over $100 million in Bitcoin stolen
- AnchorWatch CEO Rob Hamilton says OpenAI restricted his access, forcing him to use Chinese open-source AI models for his research
- OpenSats launched a Code RED grant track to pay researchers who disclose flaws and cover their AI costs
Volunteer security researchers have filed nearly 5,000 vulnerability reports across the Bitcoin ecosystem in a rapid security audit triggered by a major hardware wallet hack.
Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7
We're running a large-scale ecosystem security audit across bitcoin code bases.
27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues.
We're at… pic.twitter.com/iRCylprbY1
— calle (@callebtc) August 5, 2026
The Bitcoin Red Team reviewed 391 open-source codebases and found 4,962 security issues. Only one project came back clean.
Of all the findings, 720 were rated high or critical. That works out to about 14.5% of everything filed. Just 147 of those serious issues have so far reached the developers responsible for fixing them.
What Triggered the Audit
The sweep started after Coinkite disclosed on July 30 that seed generation on affected Coldcard devices had fallen back to a predictable software routine. Only 32 bits came from the secure element, meaning an attacker could search all possible keys with around 4.3 billion guesses.
Galaxy Research pegged confirmed thefts at 1,596 Bitcoin from roughly 7,300 addresses as of August 4. A suspected fourth attack wave could bring total losses to nearly $130 million.
The Coldcard breach pushed active Bitcoin addresses to a 20-month high on-chain.
Where the Vulnerabilities Were Found
Despite the Coldcard connection, hardware wallets ranked second lowest for serious flaws at 9.6%. Mining pools came in highest at 21.7%, followed by infrastructure and tooling at 21.5%, and swaps and exchanges at 20.9%.
Crypto libraries produced the most raw findings. They accounted for 1,385 issues across 128 projects, more than a quarter of the total.
About 21.4% of findings came with working proof-of-concept code. Roughly 91% were found through automated scanning.
One hour of that 30-hour campaign absorbed 4,101 findings alone. That spike was a backfill from AnchorWatch CEO Rob Hamilton’s earlier solo review, in which he spent over $10,000 scanning more than 100 libraries.
Calle, the pseudonymous physicist behind the Cashu ecash protocol, said project owners have been confirming the most serious reports quickly.
AI Access Restrictions Hamper Defenders
Hamilton said OpenAI restricted his access the morning after he began integrating its Trust and Cyber capabilities into his Red Team work. He said the restriction stopped him from continuing his investigation.
He said he had no choice but to return to Chinese open-source AI models to carry on his research, calling it a gut punch as an American.
Hamilton argued that those who break rules face no such restrictions, while researchers trying to reduce harm are being sidelined.
OpenSats responded by launching a Code RED grant track. It pays researchers for valid disclosures and reimburses their AI costs.
Bitcoin was trading near $64,396 at the time of reporting, up 0.5% over 24 hours. The audit has not moved the market.







