Bitcoin Red Team Finds Nearly 5,000 Potential Security Flaws Across 390 Projects
The Bitcoin Red Team, an independent initiative launched in response to a recent vulnerability affecting some Coldcard hardware wallets, has completed one of its largest security reviews ever.
The team found nearly 5,000 potential vulnerabilities across 390 open-source Bitcoin projects, including software libraries used by many applications. The audit was prompted by the Coldcard incident, which allowed attackers to steal around $100 million worth of BTC from thousands of affected addresses.
The security review identified a mix of low-risk bugs and critical security flaws, with over 14% of all findings classified as High or Critical. Around 91% of vulnerabilities were discovered using automated AI-powered scanning, while about 21% included working proof-of-concept demonstrations showing how the issue could potentially be exploited.
The report highlights the need for ongoing security reviews in Bitcoin's growing open-source infrastructure, with developers hoping to strengthen the ecosystem and reduce the risk of future attacks. The initiative has also attracted support from OpenSats, a nonprofit organization that funds Bitcoin development and provides incentives for researchers who responsibly report software vulnerabilities.