Bitcoin Red Team Identifies 1,000+ Critical Vulnerabilities in 390 Projects Using AI

iconCryptoBriefing
Share
AI summary iconSummary
Bitcoin news: A Bitcoin Red Team of 16 volunteers uncovered 4,962 security findings, including 85 critical and 635 high-severity issues, across 390 open-source Bitcoin-related projects in 30 hours. The effort, sparked by a Coldcard firmware flaw that caused $70 million to $114 million in losses, used AI tools like Kimi K3, GPT Sol, and GLM5.2. The team plans to open-source their custom security harness. AI + crypto news continues to highlight the role of automation in blockchain security.

A group of 16 volunteers just did in 30 hours what would normally take professional audit firms months. The Bitcoin Red Team, a grassroots security initiative, scanned roughly 390 open-source Bitcoin-related projects and surfaced 4,962 security findings, including 85 critical and 635 high-severity vulnerabilities.

The effort wasn’t academic. It was triggered by a very real, very expensive disaster.

The Coldcard exploit that started it all

The Bitcoin Red Team’s audit sprint was a direct response to a firmware vulnerability in Coldcard hardware wallets. That flaw, buried in the device’s random-number generator, led to estimated losses between $70 million and $114 million in stolen Bitcoin.

In English: the thing responsible for generating your private keys was broken, which meant attackers could predict those keys.

Advertisement

The scale of the losses caught the attention of Calle, a well-known Bitcoin developer, and Rob Hamilton, CEO of AnchorWatch. Together they organized the Red Team campaign in late July and early August 2026, assembling volunteers and securing funding from OpenSats, the open-source Bitcoin grant organization.

Total expenditures for the initiative came in at over $40,000.

How AI supercharged the audit

The team leaned heavily on open-weight AI models to accelerate the scanning process. The toolkit included models like Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, each deployed through a custom-built security harness designed specifically for this kind of rapid vulnerability discovery. The team plans to open-source that harness.

Across the 16 volunteers working over the roughly 30-hour sprint, the team averaged approximately 2.31 high or critical findings per person-hour.

The verification problem

Only about 21.4% of the findings had been independently reproduced at the time of reporting.

The team filed their results directly with project maintainers, creating a pipeline for responsible disclosure.

What this means for investors

The Coldcard exploit that catalyzed this effort is a case study in how hardware wallet security failures can translate directly into financial losses. Somewhere between $70 million and $114 million in Bitcoin disappeared because of a single firmware bug in a device marketed as the gold standard of self-custody.

For investors, users who rely on hardware wallets should be tracking whether their device manufacturers participate in third-party security audits and bug bounty programs.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.