Bitcoin Red Team Flags Thousands of Security Issues Across Open-Source Projects
The Bitcoin Red Team has completed an extensive review of open-source Bitcoin projects, identifying 7,958 security issues across 501 repositories. This marks a significant increase from the 4,962 findings reported on August 5, which spanned 390 projects.
The review was conducted by 25 developers over 108 hours, utilizing AI-powered tools and human analysis to accelerate code review. The team employed Moonshot AI's Kimi K3 model alongside other AI models, with OpenSats funding the compute costs through its dedicated Bitcoin Red Team programme.
The findings include 1,280 reports rated high or critical severity, which must be validated by project maintainers before patches are released. Unmaintained repositories pose a particular challenge, as AI can identify exploitable weaknesses without an active development team to investigate or patch them.
The review has already led to the discovery of a critical vulnerability in BTCPay Server's version 2.4.2, which allowed attackers to steal funds from affected users. The issue was patched, and BTCPay committed 0.21 BTC to Craig Raw and another 0.21 BTC to the Bitcoin Red Team for responsible disclosure and analysis.