Bitcoin Red Team Flags Over 4,900 Potential Security Risks in AI-Assisted Sweep
The Bitcoin Red Team conducted an AI-assisted review of 390 open-source Bitcoin projects in just 30 hours, identifying 4,962 potential security findings. This includes 85 possible critical flaws and 635 high-severity findings.
The team used AI models to scan repositories, identify suspicious code, and help researchers test possible attack paths. They searched for weak randomness, access errors, memory faults, and unsafe software interactions.
Human testing is necessary to separate signals from false alarms, as automated reviews can generate false positives, duplicate reports, and issues that real systems cannot exploit. The team reproduced only 21.4% of all reports during the review.
The campaign followed a recent discovery of a serious seed-generation flaw in several Coldcard hardware wallet firmware versions. Attackers reportedly stole about 1,816 BTC from over 5,200 addresses across four waves of suspicious transactions, worth an estimated $116 million at the time.