Bitcoin Red Team Finds Over 4,900 Vulnerabilities Across Ecosystem
A group of volunteer developers, known as the Bitcoin Red Team, has been reviewing codebases across the Bitcoin ecosystem and found nearly 5,000 vulnerabilities in about 30 hours. The team reported that one out of seven findings was critical or high-severity.
Out of 4,962 security findings filed by the Bitcoin Red Team, 85 were critical and 635 were high-severity issues. The majority of the findings came from automated scanning, with only about 21% accompanied by working proof-of-concept code.
The review found that crypto libraries produced the most vulnerabilities, accounting for over a quarter of the total corpus. On the other hand, hardware wallets and firmware had one of the lowest rates of serious flaws at 9.6%. Mining pools fared worse, with 21.7% of findings being critical or high-severity.
The Bitcoin Red Team's effort was sparked by the recent Coldcard hack, which revealed a predictable software routine in seed generation on affected devices. This vulnerability allowed attackers to guess the seeds within about 4.3 billion attempts.