Bitcoin Red Team Uncovers 4,962 Vulnerabilities in 390 Open-Source Projects
The Bitcoin Red Team, a volunteer security group, has uncovered an astonishing 4,962 vulnerabilities in 390 open-source Bitcoin projects after the Coldcard hack. This is not just a number, it's a stark reminder of the risks that come with using self-custody wallets.
The team, led by BTC dev Calle and Rob Hamilton, CEO of Anchorwatch, spent an intense 27.5 hours combing through these projects, combining AI-assisted analysis with manual review. Their findings are nothing short of alarming: 85 critical vulnerabilities were identified, alongside 635 high-severity issues.
The biggest concentration of serious flaws was found in privacy and coinjoin tools, accounting for 24% of critical findings despite making up a smaller share of the total projects reviewed. Cryptographic libraries generated the largest raw number of findings at 1,101, but only 10% were rated high-severity.
The timing of this unearthing is particularly relevant given the recent Coldcard losses, which drained bitcoin from long-term holders after a firmware bug dating to March 2021. Losses have climbed past $116 million across more than 1,800 BTC pulled from over 5,200 addresses.